CVE-2024-45256
Last modified
CVE-2024-45256 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.. EPSS estimates a 5.63% chance of exploitation in the next 30 days.
Description
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-45256?
How severe is CVE-2024-45256?
How do I fix CVE-2024-45256?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-4525A vulnerability has been found in Campcodes Complete Web-Bas…6.1
- CVE-2024-45250ZKteco – CWE 200 Exposure of Sensitive Information to an Una…4.3
- CVE-2024-45251Elsight – CWE-78: Improper Neutralization of Special Element…9.8
- CVE-2024-45252Elsight – CWE-78: Improper Neutralization of Special Element…9.8
- CVE-2024-45253Avigilon – CWE-22: Improper Limitation of a Pathname to a Re…7.5
- CVE-2024-45254VaeMendis - CWE-79: Improper Neutralization of Input During …7.5
- CVE-2024-45257A Command Injection issue in the payload build page in BYOB …7.3
- CVE-2024-45258The req package before 3.43.4 for Go may send an unintended …9.8
- CVE-2024-45259An issue was discovered on certain GL-iNet devices, includin…6.5
- CVE-2024-4526A vulnerability was found in Campcodes Complete Web-Based Sc…6.1
- CVE-2024-45260An issue was discovered on certain GL-iNet devices, includin…8
- CVE-2024-45261An issue was discovered on certain GL-iNet devices, includin…8
Are you affected by CVE-2024-45256?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
