Junglewise Threat Intelligence

CVE-2024-57968: Advantive VeraCore Unrestricted File Upload Vulnerability

CVE-2024-57968 · Severity: critical · CVSS 9.9 · Exploited in the wild · Published 2025-03-10

Executive brief

Advantive VeraCore contains an unrestricted file upload vulnerability in upload.aspx. Remote authenticated attackers can upload files to unintended, web-accessible folders, potentially leading to remote code execution.

Affected products

  • Advantive VeraCore before 2024.4.2.1

Timeline

  • 2025-02-03: disclosed: NVD Published Date
  • 2025-03-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-10: advisory: Advisory published date

Related threats