CVE-2024-5383
Last modified
CVE-2024-5383 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown part of the file /sys/file/upload. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown part of the file /sys/file/upload. The manipulation of the argument file leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier of the patch is 9c8a836ace17a93c45e5ad52a2340788b7795030. It is recommended to apply a patch to fix this issue. The identifier VDB-266301 was assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lakernote | Easyadmin | <= 2024-03-24 |
References
- https://gitee.com/lakernote/easy-admin/issues/I9B58IExploit, Issue Tracking
- https://vuldb.com/?ctiid.266301Permissions Required, VDB Entry
- https://vuldb.com/?id.266301Third Party Advisory, VDB Entry
- https://gitee.com/lakernote/easy-admin/issues/I9B58IExploit, Issue Tracking
- https://vuldb.com/?ctiid.266301Permissions Required, VDB Entry
- https://vuldb.com/?id.266301Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5383?
How severe is CVE-2024-5383?
How do I fix CVE-2024-5383?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-53824Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2024-53825Missing Authorization vulnerability in Ninja Team Filebird f…7.2
- CVE-2024-53826Missing Authorization vulnerability in WPSight WPCasa wpcasa…5.3
- CVE-2024-53827Ericsson Packet Core Controller (PCC) contains a vulnerabili…7.5
- CVE-2024-53828Ericsson Packet Core Controller (PCC) versions prior to 1.38…5.3
- CVE-2024-53829CodeChecker is an analyzer tooling, defect database and view…8.2
- CVE-2024-53832A vulnerability has been identified in CPCI85 Central Proces…5.1
- CVE-2024-53833In prepare_response_locked of lwis_transaction.c, there is …7.8
- CVE-2024-53834In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, the…7.5
- CVE-2024-53835there is a possible biometric bypass due to an unusual root …7.8
- CVE-2024-53836In wbrc_bt_dev_write of wb_regon_coordinator.c, there is a p…6.7
- CVE-2024-53837In prepare_response of lwis_periodic_io.c, there is a possib…7.8
Are you affected by CVE-2024-5383?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
