CVE-2024-9280 is a critical unrestricted file upload vulnerability in kalvinGit kvf-admin, specifically within the fileUpload function of FileUploadKit.java. This flaw allows remote attackers to upload arbitrary files, leading to potential complete compromise of confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8. While no active exploitation has been confirmed and community discussion is minimal, the exploit details have been publicly disclosed, posing an immediate risk to unpatched systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2022-02-12CPE matchmatch criteria | cpe:2.3:a:kvf-admin_project:kvf-admin:2022-02-12:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.