Sploitus

CVE-2024-27171

1 known exploit for CVE-2024-27171

A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affected products/models/versions, see the reference URL.

CVSS 3.1
7.4 HIGH
EPSS
0.5% (41th percentile)
Weakness
CWE-276
NVD status
Deferred
Published
2024-06-14
Attack patterns
CAPEC-180

Fix

This issue is fixed in the version released on June 14, 2024 and all later versions.

CVE-2024-27171 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-27171

Proof-of-concept code and exploit modules indexed by Sploitus