CVE-2024-29272

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-29272
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29272.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-29272
Aliases
Published
2024-03-22T04:15:11Z
Modified
2025-01-14T12:15:36.877030Z
Summary
[none]
Details

Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.

References

Affected packages

Git / github.com/givanz/vvvebjs

Affected ranges

Type
GIT
Repo
https://github.com/givanz/vvvebjs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.2
1.2.2
1.3
1.4
1.4.1
1.5
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.4

Other

untagged-f29f41112fa37268b3e1

v1.*

v1.0
v1.1