Логотип exploitDog
bind: "CVE-2024-58294"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-58294"

Количество 2

Количество 2

nvd логотип

CVE-2024-58294

около 2 месяцев назад

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f55-6gfh-8xfx

около 2 месяцев назад

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-58294

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.

CVSS3: 8.8
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-3f55-6gfh-8xfx

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.

CVSS3: 8.8
1%
Низкий
около 2 месяцев назад

Уязвимостей на страницу