Vulnerability record · CVE-2024-57968 · published 3 February 2025
CVE-2024-57968: Advantive VeraCore unrestricted file upload via upload.aspx
Advantive · Veracore
VeraCore before 2024.4.2.1 lets an authenticated user upload files to unintended folders, including locations reachable through web browsing by other users. Because the upload path is not properly restricted, a low-privileged account can place attacker-controlled content where it can be served or executed, which is why this is in CISA KEV.
Description
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with a high EPSS score and public exploit detail, but exploitation requires an authenticated low-privileged account rather than being unauthenticated.
What it is
VeraCore before 2024.4.2.1 lets an authenticated user upload files to unintended folders, including locations reachable through web browsing by other users. Because the upload path is not properly restricted, a low-privileged account can place attacker-controlled content where it can be served or executed, which is why this is in CISA KEV.
Impact
An attacker with a valid low-privileged account can write files into web-accessible directories, enabling content injection, hosting of malicious payloads, or code execution depending on server configuration. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network through the upload.aspx endpoint; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). No unauthenticated path is described in the record.
Exploitation
Listed in CISA KEV with a due date of 2025-03-31, and EPSS shows a 30-day probability of 0.323 (98th percentile). Two third-party references are tagged as exploit and technical description, indicating public technical detail exists; KEV notes no known ransomware campaign use.
What to do
- Upgrade VeraCore to 2024.4.2.1 or later per the vendor release notes.
- If patching is not immediately possible, restrict or disable upload.aspx and limit upload destinations to non-web-accessible directories.
- Remove write permissions to web-served directories from the application service account.
- Audit and remove any unexpected files already written to web-accessible folders.
- Apply the vendor mitigations referenced in the CISA KEV entry and follow BOD 22-01 guidance for cloud instances.
Detection
- Monitor upload.aspx requests for writes to paths outside the expected upload directory.
- Alert on new executable or script files appearing in web-accessible directories.
- Review web server logs for access to recently uploaded files by other users.
- Baseline and monitor the VeraCore service account for file creation outside its normal upload path.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-57968 to the Known Exploited Vulnerabilities catalog on 10 March 2025 as "Advantive VeraCore Unrestricted File Upload Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 31 March 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://advantive.my.site.com/support/s/article/VeraCore-Release-Notes-2024-4-2-1 | Permissions RequiredProductRelease Notes |
| https://intezer.com/blog/research/xe-group-exploiting-zero-days/ | ExploitTechnical DescriptionThird Party Advisory |
| https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/ | ExploitTechnical DescriptionThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57968 | US Government Resource |
Track CVE-2024-57968 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-57968), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.