ZeroHour

CVE-2024-50625

CVSS 3.1
8.0 high
EPSS
<1%p24
Published
()
Modified
Description

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when combined with other vulnerabilities.

Vendors
digi
Products
connectport lts firmware
Weakness
CWE-434
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.