CVE-2024-50620Disclosure(cipplanner / cipace)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce before 9.17. An authorized user can upload executable files when inserting images in the rich text editor, and upload executable files when uploading files on the document management page. Those executables can be executed if they are not stored in a shared directory or if the storage directory has executed permissions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cipace

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
cipace

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-18: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-18: 102-1102-18
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-181
General1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2024-50620 Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce before 9.17. An auth… https://www.cve.org/CVERecord?id=CVE-2024-50620

    Post summary

    CVE-2024-50620 details an unrestricted upload vulnerability in CIPPlanner CIPAce (pre‑9.17) affecting the rich text editor and document management components, allowing upload of dangerous file types.

    00010352
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    General

    [CVE-2024-50620: HIGH] Beware of unrestricted file upload vulnerabilities in CIPPlanner CIPAce (before 9.17) allowing execution of dangerous files. Exercise caution to prevent cyber threats. #CyberSecurity#cve,CVE-2024-50620,#cybersecurity https://cvefind.com/CVE-2024-50620

    Post summary

    The post warns about a high‑severity unrestricted file upload flaw in CIPPlanner CIPAce (pre‑9.17) that could allow execution of dangerous files, but does not provide a PoC, exploit code, active exploitation evidence, or patch information.

    0000098
    578 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcipplannercipace---

Explore more