Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-45136


InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be executed on the server. Exploitation of this issue requires user interaction.


Published

2024-10-09T15:15:13.163

Last Modified

2024-10-18T14:20:49.137

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe incopy < 18.5.4 Yes
Application adobe incopy < 19.5 Yes
Operating System apple macos - No
Operating System microsoft windows - No

References