Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29272


Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.


Published

2024-03-22T04:15:11.663

Last Modified

2025-05-28T19:00:50.340

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vvveb vvvebjs < 1.7.5 Yes

References