CVE-2024-29848

Publication date

2024-05-31 17:38:31

Family

hackerone

State

PUBLISHED

Description

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.