← back
CVE-2024-29272mediumCWE-434

CVE-2024-29272

28Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 6.5epss 9.4%
exploitation probability
9.4%top 5% of all CVEs
observed exploitation
nono source reports it
Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
n/a · n/a