CVE-2024-57968
About
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
Rainforest analyst review
Advantive VeraCore before 2024.4.2.1 mishandles file uploads in upload.aspx: an authenticated user can direct uploaded files into folders other than the intended upload location, including directories that are served to and browsed by other users over the web. By placing an executable server-side file such as an ASPX page into a web-accessible path, an attacker turns an unrestricted upload into remote code execution on the server, needing only low-privilege credentials.
VeraCore is a warehouse and order-management platform used by fulfillment and third-party logistics providers, so the servers hold operational and customer order data and connect fulfillment workflows. This flaw was reported as exploited in the wild, chained with a separate VeraCore SQL injection by an actor tracked as XE Group to deploy web shells and maintain long-running access. Upgrade to the fixed VeraCore release, and because the exploitation predates many organizations' awareness, hunt the web-accessible directories for unexpected uploaded scripts and web shells and review upload.aspx activity rather than assuming the patch alone evicts an established intruder.
References
- https://advantive.my.site.com/support/s/article/VeraCore-Release-Notes-2024-4-2-1
- https://intezer.com/blog/research/xe-group-exploiting-zero-days/
- https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57968
Related CVEs
Frequently asked questions
What is CVE-2024-57968?
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
How severe is CVE-2024-57968?
CVE-2024-57968 carries a CVSS 3.1 base score of 9.9, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2024-57968 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2024-57968?
Public advisories list the following as affected: veracore. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2024-57968?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
