← Back to browse · API

CVE-2024-2599

Severity
CRITICAL
CVSS
9.9
EPSS
0.00623
Risk score
39.82
CISA KEV
No
PoC
No
Published
2024-03-18
Modified
2024-08-12
First seen
2026-08-07
Aliases
EUVD-2024-27548, GHSA-3X7R-CVW4-596J
Products
AMSS++:AMSS++, AMSS++:AMSS++ 4.31
Sources
euvd EUVD-2024-27548

Description

File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire infrastructure.

References