CVE Database
/

CVE-2024-8525

Back to search

CVE-2024-8525

Published: Nov 21, 2024

Modified: Nov 21, 2024

PUBLISHED

Description

An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execution via a crafted HTTP POST request which could lead to uploading a malicious file.

VendorProductVersions

Automated Logic, a Carrier company

WebCTRL

affected
7.0

Carrier

i-Vu

affected
7.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now