CVE-2024-33120
roothub
Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.
- CVSS
- 9.8
- EPSS
- 0.77% 52.2% percentile
- CISA KEV
- Not listed
- Published
- 2024.05.08