CVE-2024-29640: Messense Aliyundrive-Webdav
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the action_query_qrcode component.
Affected products
- Messense Aliyundrive-Webdav: up to and including 2.3.3
Published 2024-03-29. Last modified 2026-07-09.