ZeroHour

CVE-2024-57968

KEV PoC ×2niche1

Unrestricted File Upload in Advantive VeraCore upload.aspx

CISA: Advantive VeraCore Unrestricted File Upload Vulnerability

CVSS 3.1
8.8 high
EPSS
32%p98
Published
()
KEV added
AI analysis

Advantive VeraCore, a warehouse management and order fulfillment platform, contains an unrestricted file upload flaw (CWE-434) in its upload.aspx endpoint that fails to properly restrict what files can be uploaded and where they are stored. A remote attacker with no credentials can abuse the endpoint to write files into unintended, attacker-influenced folders on the server. By placing crafted files (for example, script files) into web-reachable directories, an attacker can typically escalate an arbitrary upload into webshell deployment and code execution on the hosting server. Any organization running VeraCore, especially instances with the upload endpoint reachable from the internet, is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-10, indicating active exploitation, and EPSS assigns a 32.3% probability of exploitation within 30 days (98th percentile).

What to do: Apply the mitigations required under CISA KEV/BOD 22-01, following Advantive's instructions, and contact the vendor for the fixed release since no patched version is specified in the available data. In the interim, restrict network access to upload.aspx (allow only trusted users or VPN/internal traffic), enforce file-type and destination validation at a WAF/reverse proxy where possible, and hunt for unexpected or recently modified files in VeraCore's web directories plus suspicious entries in web access logs to detect webshells or uploaded payloads.

Affected
Advantive VeraCore
Estimated exposure
nicheroughly hundreds to low thousands of deployments (fulfillment/3PL and e-commerce operations running VeraCore) — VeraCore is a specialized warehouse/fulfillment management system with a customer base concentrated in the 3PL and e-commerce fulfillment vertical, so the installed base is plausibly in the hundreds-to-low-thousands of sites rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.

CISA Known Exploited Vulnerability
Affected
Advantive VeraCore
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
advantive
Products
veracore
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news