Vulnerabilities > Wellchoose

DATE CVE VULNERABILITY TITLE RISK
2024-10-21 CVE-2024-10200 Path Traversal vulnerability in Wellchoose Administrative Management System
Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to download arbitrary files on the server.
network
low complexity
wellchoose CWE-22
7.5
2024-10-21 CVE-2024-10201 Unrestricted Upload of File with Dangerous Type vulnerability in Wellchoose Administrative Management System
Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells.
network
low complexity
wellchoose CWE-434
8.8
2024-10-21 CVE-2024-10202 OS Command Injection vulnerability in Wellchoose Administrative Management System
Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
network
low complexity
wellchoose CWE-78
8.8