go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Ai3 QbiBot - Unrestricted File Upload

TVN ID TVN-202404005
CVE ID CVE-2024-3778
CVSS 7.2 (High)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products QbiBot v8.0.4 and earlier version
Description The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privilege to upload files with dangerous type containing malicious code.
Solution Update to v8.0.5 or latter version, or contact vendor for remediation
Credit Huding(DEVCORE)
Public Date 2024-04-15
Top