Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53440 | Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of the UploadFile element in a SOAP request to /XSDService.asmx. |
Mon, 06 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Jan 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of the UploadFile element in a SOAP request to /XSDService.asmx. | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-06T20:36:04.563Z
Reserved: 2025-01-02T00:00:00.000Z
Link: CVE-2024-56829
Updated: 2025-01-06T20:35:58.300Z
Status : Deferred
Published: 2025-01-02T04:15:05.557
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-56829
No data.
OpenCVE Enrichment
No data.
EUVD