Логотип exploitDog
bind:CVE-2026-24452
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-24452

Количество 2

Количество 2

nvd логотип

CVE-2026-24452

около 1 месяца назад

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-26rx-qf83-fc58

около 1 месяца назад

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-24452

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.

CVSS3: 8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-26rx-qf83-fc58

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.

CVSS3: 8
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу