CVE-2024-1577
CVSS V2 None
CVSS V3 None
Description
Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP software versions through 5.11.2.
Overview
- CVE ID
- CVE-2024-1577
- Assigner
- CERT-PL
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-06-12T13:47:31.899Z
- Last Modified Date
- 2024-06-20T20:14:26.736Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://cert.pl/en/posts/2024/06/CVE-2024-1576/ | third-party-advisory |
https://cert.pl/posts/2024/06/CVE-2024-1576/ | third-party-advisory |
https://megabip.pl/ | product |
https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej | government-resource |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-1577 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1577 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 06:17:52 | Added to TrackCVE |