A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data
History

Wed, 29 Jan 2025 12:45:00 +0000


Wed, 29 Jan 2025 11:45:00 +0000


Mon, 27 Jan 2025 11:15:00 +0000

Type Values Removed Values Added
Description Arbitrary file upload, deletion and read through header manipulation A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data

Thu, 23 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Arbitrary file upload, deletion and read through header manipulation
Title Arbitrary file upload, deletion and read through header manipulation
Weaknesses CWE-22
CWE-434
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Xerox

Published:

Updated: 2025-01-29T11:34:21.634Z

Reserved: 2024-12-13T14:30:30.206Z

Link: CVE-2024-55926

cve-icon Vulnrichment

Updated: 2025-01-23T18:58:21.066Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-23T18:15:31.780

Modified: 2025-01-29T12:15:28.873

Link: CVE-2024-55926

cve-icon Redhat

No data.