CVE-2024-48093
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
30/10/2024
Last modified:
01/11/2024
Description
Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.
Impact
Base Score 3.x
8.00
Severity 3.x
HIGH



