← Back to CVE List

CVE-2024-52302

Published: 2024-11-14T16:15Z
Last Modified: 2024-11-15T13:58Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions, enabling attackers to upload malicious files that can lead to Remote Code Execution (RCE). > MITRE Terms of Use apply – see LICENSE‑MITRE.txt