Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Advantive VeraCore Upload Validation Vulnerability Allowing File Uploads to Unintended Directories

Vulnerability

An upload validation vulnerability has been identified in Advantive VeraCore versions prior to 2024.4.2.1. This vulnerability allows remote authenticated users to upload files to unintended directories that may be accessible during web browsing by other users. The issue arises because the application only verifies the size of the uploaded files, and if not properly configured, the uploaded files can be accessed via the web server.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads, which could be used to execute malicious code or access sensitive information, depending on the nature of the uploaded files.

Reproduction

The vulnerability can be reproduced by logging into the VeraCore application and navigating to the upload feature. Once authenticated, files can be uploaded to various directories, including those that are publicly accessible through the web server.

Remediation

Users are advised to update to Advantive VeraCore version 2024.4.2.1 or later, where this vulnerability has been addressed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.0
remediation
7.7
relevance
0.0
threat
8.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.