CVE Vulnerabilities

CVE-2024-24122

Published: Oct 02, 2024 | Modified: Nov 13, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A remote code execution vulnerability in the project management of Wanxing Technologys Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project file into the system startup folder, restart the system, and automatically execute the constructed attack script.

Affected Software

Name Vendor Start Version End Version
Edraw Wondershare 3.2.2 (including) 3.2.2 (including)

References