CVE-2024-29640: Messense Aliyundrive-Webdav

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the action_query_qrcode component.

Affected products

  • Messense Aliyundrive-Webdav: up to and including 2.3.3

Published 2024-03-29. Last modified 2026-07-09.