← Vulnerability feed

Vulnerability record · CVE-2024-57968 · published 3 February 2025

CVE-2024-57968: Advantive VeraCore unrestricted file upload via upload.aspx

Advantive · Veracore

VeraCore before 2024.4.2.1 lets an authenticated user upload files to unintended folders, including locations reachable through web browsing by other users. Because the upload path is not properly restricted, a low-privileged account can place attacker-controlled content where it can be served or executed, which is why this is in CISA KEV.

8.8 CVSS 3.1 High CISA KEV since 10 Mar 2025 EPSS 32% · top 1.7% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score
32%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with a high EPSS score and public exploit detail, but exploitation requires an authenticated low-privileged account rather than being unauthenticated.

What it is

VeraCore before 2024.4.2.1 lets an authenticated user upload files to unintended folders, including locations reachable through web browsing by other users. Because the upload path is not properly restricted, a low-privileged account can place attacker-controlled content where it can be served or executed, which is why this is in CISA KEV.

Impact

An attacker with a valid low-privileged account can write files into web-accessible directories, enabling content injection, hosting of malicious payloads, or code execution depending on server configuration. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network through the upload.aspx endpoint; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). No unauthenticated path is described in the record.

Exploitation

Listed in CISA KEV with a due date of 2025-03-31, and EPSS shows a 30-day probability of 0.323 (98th percentile). Two third-party references are tagged as exploit and technical description, indicating public technical detail exists; KEV notes no known ransomware campaign use.

What to do

  • Upgrade VeraCore to 2024.4.2.1 or later per the vendor release notes.
  • If patching is not immediately possible, restrict or disable upload.aspx and limit upload destinations to non-web-accessible directories.
  • Remove write permissions to web-served directories from the application service account.
  • Audit and remove any unexpected files already written to web-accessible folders.
  • Apply the vendor mitigations referenced in the CISA KEV entry and follow BOD 22-01 guidance for cloud instances.

Detection

  • Monitor upload.aspx requests for writes to paths outside the expected upload directory.
  • Alert on new executable or script files appearing in web-accessible directories.
  • Review web server logs for access to recently uploaded files by other users.
  • Baseline and monitor the VeraCore service account for file creation outside its normal upload path.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-57968 to the Known Exploited Vulnerabilities catalog on 10 March 2025 as "Advantive VeraCore Unrestricted File Upload Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 31 March 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-57968 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2025-25181Advantive VeraCore SQL injection in timeoutWarning.aspVeraCore through 2025.1.0 contains a SQL injection flaw in timeoutWarning.asp reachable through the PmSess1 parameter. A remote, unauthenticated atta…KEVEPSS 57%analysed10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed10.0CVE-2026-48908SP Page Builder for Joomla unauthenticated arbitrary file upload RCESP Page Builder for Joomla permits unauthenticated users to upload arbitrary files, which can lead to upload and execution of PHP code. The flaw is a…KEVEPSS 89%analysed9.8CVE-2024-7399Samsung MagicINFO 9 Server path traversal allows arbitrary file writeSamsung MagicINFO 9 Server before version 21.1050 contains a path traversal flaw (CWE-22) that also enables unrestricted file upload (CWE-434), letti…KEVEPSS 92%analysed7.2CVE-2025-2749Kentico Xperience path traversal and file upload lead to RCEKentico Xperience through 13.0.178 allows an authenticated Staging Sync Server user to upload arbitrary data to relative paths, enabling path travers…KEVEPSS 4.1%analysed7.2CVE-2024-7694ThreatSonar Anti-Ransomware unrestricted file upload enables command executionThreatSonar Anti-Ransomware from TeamT5 fails to properly validate the content of uploaded files (CWE-434). An attacker holding administrator privile…KEVEPSS 1.8%analysed

Source: NIST National Vulnerability Database (record CVE-2024-57968), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.