CVE-2024-3778

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
15/04/2024
Last modified:
08/04/2025

Description

The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privilege to upload files with dangerous type containing malicious code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ai3:qbibot:-:*:*:*:*:*:*:*