U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-0713

Change History

CVE Translated by VulDB 4/25/2024 2:15:53 AM

Action Type Old Value New Value
Removed Translation
Title: Monitorr 1.7.6m
Description: Se encontró una vulnerabilidad en Monitorr 1.7.6m. Ha sido declarada crítica. Una función desconocida del archivo /assets/php/upload.php del componente Services Configuration es afectada por esta vulnerabilidad. La manipulación del argumento fileToUpload conduce a una carga sin restricciones. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. El identificador asociado de esta vulnerabilidad es VDB-251539. NOTA: Se contactó primeramente con el proveedor sobre esta divulgación, pero no respondió de ninguna manera.

								
						

CVE Modified by VulDB 4/25/2024 2:15:53 AM

Action Type Old Value New Value
Changed Description
A vulnerability was found in Monitorr 1.7.6m. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /assets/php/upload.php of the component Services Configuration. The manipulation of the argument fileToUpload leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251539. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-28871. Reason: This candidate is a reservation duplicate of CVE-2020-28871. Notes: All CVE users should reference CVE-2020-28871 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Removed CVSS V3.1
NIST AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

								
						
Removed CVSS V3.1
VulDB AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

								
						
Removed CVSS V2
VulDB (AV:N/AC:L/Au:M/C:P/I:P/A:P)

								
						
Removed CWE
VulDB CWE-434

								
						
Removed CPE Configuration
OR
     
          *cpe:2.3:a:monitorr:monitorr:1.7.6m:*:*:*:*:*:*:*

								
						
Removed Reference
VulDB https://drive.google.com/file/d/1C6_4A-96BtR9VTNSadUY09ErroqLEVJ4/view?usp=sharing

								
						
Removed Reference
VulDB https://vuldb.com/?ctiid.251539

								
						
Removed Reference
VulDB https://vuldb.com/?id.251539

								
						

CVE Rejected by VulDB 4/25/2024 2:15:53 AM

Action Type Old Value New Value