CVE-2024-52302 is a critical vulnerability in the common-user-management Spring Boot application, specifically in the /api/v1/customer/profile-picture endpoint. The endpoint permits file uploads without adequate validation or restrictions, allowing attackers to upload arbitrary files, including those containing executable code. This flaw can be exploited to achieve Remote Code Execution (RCE) on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains an exploit for CVE-2024-52302, an unrestricted file upload vulnerability in the 'common-user-management' Spring Boot application. The exploit consists of a Python script (exploit.py) and a detailed README.md. The script authenticates to the target application using provided credentials, then uploads an arbitrary file (such as a web shell) to the vulnerable /api/v1/customer/profile-picture endpoint. The README explains the vulnerability, exploitation steps, and provides usage instructions for the script. The exploit leverages network access to the application's API endpoints and requires valid user credentials. If successful, it enables remote code execution on the target server by uploading and executing a malicious file. The repository is well-structured, with clear separation between documentation and exploit code, and focuses on operational exploitation rather than detection or proof-of-concept only.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.