Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-27115

Опубликовано: 11 сент. 2024
Источник: nvd
CVSS3: 9.8
EPSS Высокий

Описание

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:*
Версия до 1.52.02 (исключая)

EPSS

Процентиль: 99%
0.8037
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-434
CWE-434

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.

EPSS

Процентиль: 99%
0.8037
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-434
CWE-434