CVE-2024-52302
common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
- Published
- Nov 14, 2024
- Updated
- Nov 14, 2024
- Assigning CNA
- GitHub_M
- Evidence observed
- Apr 15, 2025
common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
nvd · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLow · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions, enabling attackers to upload malicious files that can lead to Remote Code Execution (RCE).
PoC exploit for CVE-2024-52302: unrestricted file upload in common-user-management Spring Boot app leading to remote code execution via /api/v1/customer/profile-picture endpoint.
Reproduction environment for CVE-2024-52302, providing a proof-of-concept exploit to demonstrate and test the vulnerability in a controlled setting.
d3sca · java · Apr 15, 2025
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.