Join THREATCON1 in Reston, VA - September 21-22, 2025.
Register for Free
Products
Government
Resources
Community
Company
Partners
Sign In / Join
Sign In
Advisories
LiveBos UploadFile.do Arbitrary File Upload
Go Back
severity
critical
date
August 27, 2025
Affecting
Pre-August 2024 builds
An affected version range is undefined
CVE
CVE-2024-13981
CVE type
Path Traversal, Unrestricted File Upload
CVSS
10
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
References
CN-SEC Disclosure
CSDN Blog Disclosure (1)
CSDN Blog Disclosure (2)
CSDN Blog Disclosure (3)
GitHub PoC
Product Site
Credit
Sunuomu Security Team
Description
Exploitation evidence was first observed by the Shadowserver Foundation on 2024-08-23 UTC.
VulnCheck KEV
This advisory is in the VulnCheck KEV database