CVE-2024-33615

EUVD-2024-34477
A specially crafted Zip file containing path traversal characters can be
 imported to the 
CyberPower PowerPanel 

server, which allows file writing to the server outside
 the intended scope, and could allow an attacker to achieve remote code 
execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
icscertCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H