CVE-2024-54449
Last modified
CVE-2024-54449 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. An account with ‘read’ and ‘write’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Logicaldoc | Logicaldoc | < 9.1 |
References
- https://www.blackduck.com/blog/cyrc-advisory-logicaldoc.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-54449?
How severe is CVE-2024-54449?
How do I fix CVE-2024-54449?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-54443Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-54444Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2024-54445Login functionality contains a blind SQL injection that can …8.7
- CVE-2024-54446Document history functionality contains a blind SQL injectio…7.1
- CVE-2024-54447Saved search functionality contains a blind SQL injection th…7.1
- CVE-2024-54448The Automation Scripting functionality can be exploited by a…7.2
- CVE-2024-5445Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent v…3.8
- CVE-2024-54450An issue was discovered in Kurmi Provisioning Suite 7.9.0.33…9.4
- CVE-2024-54451A cross-site scripting (XSS) vulnerability in the graphicCus…4.8
- CVE-2024-54452An issue was discovered in Kurmi Provisioning Suite before 7…4.9
- CVE-2024-54453An issue was discovered in Kurmi Provisioning Suite before 7…7.5
- CVE-2024-54454An issue was discovered in Kurmi Provisioning Suite before 7…5.3
Are you affected by CVE-2024-54449?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
