Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17643 | A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown function of the file /app/controller/Setup.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254856. |
Wed, 18 Dec 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Osuuu
Osuuu lightpicture |
|
| CPEs | cpe:2.3:a:osuuu:lightpicture:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Osuuu
Osuuu lightpicture |
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-01T18:56:22.336Z
Reserved: 2024-02-27T07:27:51.864Z
Link: CVE-2024-1921
Updated: 2024-08-01T18:56:22.336Z
Status : Analyzed
Published: 2024-02-27T15:15:07.503
Modified: 2026-06-17T07:05:24.900
Link: CVE-2024-1921
No data.
OpenCVE Enrichment
No data.
-
CWE-434
Unrestricted Upload of File with Dangerous Type
EUVD