Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an administrator is not required) to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.
Cite this page
CVE-2024-55371. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-55371
Use CWE-73, Wallosapp vendor hub and Wallos product page to widen CVE-2024-55371 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-55372, CVE-2026-30840 and CVE-2026-30828 for nearby disclosures in the same product family.