References https://nvd.nist.gov/vuln/detail/CVE-2024-28147 https://github.com/advisories/GHSA-c87f-rj58-gx9p https://sec-consult.com/vulnerability-lab/advisory/arbitrary-file-upload-in-edu-sharing-metaventis-gmbh/ https://seclists.org/fulldisclosure/2024/Jun/11 https://sploitus.com/exploit?id=PACKETSTORM:179199 https://community.fortinet.com/blogs-103/mitigating-stored-xss-and-dos-vulnerabilities-in-edu-sharing-cve-2024-28147-182219
Related VulnerabilitiesPoCk8s-containers-share-host-ipc: Containers sharing host IPC namespacePoCk8s-host-network-namespace-shared: Host Network Namespace SharingPoCk8s-host-pid-namespace-sharing: Host PID Namespace SharingPoCunencrypted-file-sharing-enabled: Unencrypted File Sharing EnabledPoCCVE-2019-18952: Xfilesharing 2.5.1 - Arbitrary File Upload用友NC listUserSharingEvents 存在SQL注入漏洞用友 /portal/pt/oacoSchedulerEvents/listUserSharingEvents SQL 注入漏洞D-Link NAS nas_sharing.cgi 命令注入漏洞iSharer and upRedSun File Sharing Wizard 缓冲区溢出漏洞D-Link NAS /cgi-bin/nas_sharing.cgi 命令执行漏洞(CVE-2024-3273)D-Link nas_sharing.cgi 远程代码执行漏洞(CVE-2024-3273)