ZeroHour

CVE-2024-3778

CVSS 3.1
7.2 high
EPSS
<1%p49
Published
()
Modified
Description

The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privilege to upload files with dangerous type containing malicious code.

Vendors
ai3
Products
qbibot
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.