← back
CVE-2024-3778highCWE-434

Ai3 QbiBot - Unrestricted File Upload

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 0.6%
exploitation probability
0.6%top 51% of all CVEs
observed exploitation
nono source reports it
The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privilege to upload files with dangerous type containing malicious code.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Ai3 · QbiBot