« Volver al listado

CVE-2024-8940

Estado: AnalizadaCrítica (9.8)—

Vulnerabilidad en la aplicación Scriptcase versión 9.4.019, que implica la carga arbitraria de un archivo a través de /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ mediante una solicitud POST. Un atacante podría cargar archivos maliciosos al servidor debido a que la aplicación no verifica correctamente la entrada del usuario.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-8940",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-8940",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-24T13:06:32.271194Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@incibe.es",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@incibe.es",
      "affectedData": [
        {
          "vendor": "Scriptcase",
          "product": "Scriptcase",
          "versions": [
            {
              "status": "affected",
              "version": "9.4.019"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:scriptcase:scriptcase:9.4.019:*:*:*:*:*:*:*"
          ],
          "vendor": "scriptcase",
          "product": "scriptcase",
          "versions": [
            {
              "status": "affected",
              "version": "9.4.019"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-09-25T01:15:48.087",
  "references": [
    {
      "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-scriptcase",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@incibe.es"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@incibe.es",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the application not properly verifying user input."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en la aplicación Scriptcase versión 9.4.019, que implica la carga arbitraria de un archivo a través de /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ mediante una solicitud POST. Un atacante podría cargar archivos maliciosos al servidor debido a que la aplicación no verifica correctamente la entrada del usuario."
    }
  ],
  "lastModified": "2026-06-17T08:23:35.797",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:scriptcase:scriptcase:9.4.019:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE28A6BC-9B6D-4F25-9828-8D806FA48470"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@incibe.es"
}