ZeroHour

CVE-2024-8330

CVSS 3.1
8.8 high
EPSS
<1%p44
Published
()
Modified
Description

6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.

Vendors
6shr system project
Products
6shr system
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.