vendor:
Angular-Base64-Upload Library
by:
Ravindu Wickramasinghe
CVSS
Remote Code Execution (RCE)
20
CWE
Product Name: Angular-Base64-Upload Library
Affected Version From: 2000.1.20
Affected Version To: 2000.1.20
Patch Exists: YES
Related CWE: CVE-2024-42640
CPE: a:angular-base64-upload:angular-base64-upload:0.1.20
Platforms Tested: Arch Linux
2024
Angular-Base64-Upload Library 0.1.20 – Remote Code Execution (RCE)
The Angular-Base64-Upload Library version 0.1.20 is vulnerable to Remote Code Execution (RCE) prior to v0.1.21. An unauthenticated attacker can exploit this vulnerability to execute arbitrary code on the target system. This exploit has been assigned CVE-2024-42640 with a severity rating of Critical (CVSS 10.0).
Mitigation:
To mitigate this vulnerability, users are advised to update the Angular-Base64-Upload Library to version v0.1.21 or later.