CVE-2024-4748
RCE in Cruddiy
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server. The exploitation risk is limited since CRUDDIY is meant to be launched locally. Nevertheless, a user with the project running on their computer might visit a website which would send such a malicious request to the locally launched server.
El proyecto CRUDDIY es vulnerable a la inyección de comandos de shell mediante el envío de una solicitud POST manipulada al servidor de aplicaciones. El riesgo de explotación es limitado ya que CRUDDIY debe lanzarse localmente. Sin embargo, un usuario con el proyecto ejecutándose en su computadora podría visitar un sitio web que enviaría una solicitud maliciosa al servidor iniciado localmente.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-05-10 CVE Reserved
- 2024-06-24 CVE Published
- 2024-10-10 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
- CAPEC-248: Command Injection
References (3)
URL | Tag | Source |
---|---|---|
https://cert.pl/en/posts/2024/06/CVE-2024-4748 | Third Party Advisory | |
https://cert.pl/posts/2024/06/CVE-2024-4748 | Third Party Advisory | |
https://github.com/jan-vandenberg/cruddiy/issues/67 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
J11g Search vendor "J11g" | Cruddiy Search vendor "J11g" for product "Cruddiy" | <= 202312.1 Search vendor "J11g" for product "Cruddiy" and version " <= 202312.1" | - |
Affected
|