CVE-2024-29640
EUVD-2024-085129.03.2024, 17:15
An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the action_query_qrcode component.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| messense | aliyundrive-webdav | 𝑥 ≤ 2.3.3 | ADP |