CVE-2024-49209

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/10/2024
Last modified:
14/03/2025

Description

Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially exploit this vulnerability to elevate their privileges and upload additional system icons.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:archerirm:archer:*:*:*:*:*:*:*:* 2024.03 (including) 2024.09 (excluding)