RULE(RULE ID:338226)

Rule General Information
Release Date: 2024-07-02
Rule Name: Aliyundrive WebDAV Command Injection Vulnerability (CVE-2024-29640)
Severity:
CVE ID:
Rule Protection Details
Description: An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the action_query_qrcode component.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://aliyundrive-webdav.com
https://github.com/lakemoon602/vuln/blob/main/detail.md
https://github.com/messense/aliyundrive-webdav
Solutions
Please contact the software vendor to update the software patch.