← Back to browse · API

CVE-2024-8940

Severity
CRITICAL
CVSS
10.0
EPSS
0.00546
Risk score
40.19
CISA KEV
No
PoC
No
Published
2024-09-24
Modified
2024-09-24
First seen
2026-08-07
Aliases
EUVD-2024-49497, GHSA-R44H-CW52-2X2F
Products
Scriptcase:Scriptcase 9.4.019
Sources
euvd EUVD-2024-49497

Description

Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input.

References