CVE-2024-24122
Last modified
CVE-2024-24122 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and automatically execute the constructed attack script.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and automatically execute the constructed attack script.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wondershare | Edraw | 3.2.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-24122?
How severe is CVE-2024-24122?
How do I fix CVE-2024-24122?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-24112xmall v1.1 was discovered to contain a SQL injection vulnera…9.8
- CVE-2024-24113xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vu…8.8
- CVE-2024-24115A stored cross-site scripting (XSS) vulnerability in the Edi…5.4
- CVE-2024-24116An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(97…9.8
- CVE-2024-24117Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P R…9.8
- CVE-2024-2412The disabling function of the user registration page for Hei…5.3
- CVE-2024-2413Intumit SmartRobot uses a fixed encryption key for authentic…9.8
- CVE-2024-24130Mail2World v12 Business Control Center was discovered to con…6.1
- CVE-2024-24131SuperWebMailer v9.31.0.01799 was discovered to contain a ref…6.1
- CVE-2024-24133Atmail v6.6.0 was discovered to contain a SQL injection vuln…9.8
- CVE-2024-24134Sourcecodester Online Food Menu 1.0 is vulnerable to Cross S…4.8
- CVE-2024-24135Product Name and Product Code in the 'Add Product' section o…6.1
Are you affected by CVE-2024-24122?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
