{ "id": "CVE-2024-35592", "sourceIdentifier": "cve@mitre.org", "published": "2024-05-24T14:15:17.287", "lastModified": "2024-05-24T18:09:20.027", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "An arbitrary file upload vulnerability in the Upload function of Box-IM v2.0 allows attackers to execute arbitrary code via uploading a crafted PDF file." } ], "metrics": {}, "references": [ { "url": "https://github.com/Joying-C/Cross-site-scripting-vulnerability/blob/main/BOX-IM_Cross_site%20_scripting%20_vulnerability/BOX-IM_Cross_site%20_scripting%20_vulnerability.pdf", "source": "cve@mitre.org" } ] }