Angular-base64-update Demo Script Exploited (CVE-2024-42640), (Tue, Oct 15th)

SANS Internet Storm Center, InfoCON: green 2024-10-15

Summary:

Demo scripts left behind after installing applications or frameworks are an ongoing problem. After installation, removing any "demo" or "example" folders is usually best. A few days ago, Ravindu Wickramasinghe noticed that the Angular-base64-upload project is leaving behind a demo folder with a script allowing arbitrary file uploads without authentication [1]. Exploitation of the vulnerability is trivial. An attacker may use the file upload script to upload a web shell, and in response, the attacker will obtain remote command execution with all the privileges granted to the web server.

Link:

https://isc.sans.edu/diary/rss/31354

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

10/15/2024, 13:47

Date published:

10/15/2024, 11:08