CVE-2024-31390
CVSS V2 None
CVSS V3 None
Description
: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.
Overview
- CVE ID
- CVE-2024-31390
- Assigner
- Patchstack
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-04-03T11:39:23.926Z
- Last Modified Date
- 2024-05-08T08:30:06.526Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://patchstack.com/database/vulnerability/breakdance/wordpress-breakdance-plugin-1-7-0-authenticated-remote-code-execution-rce-vulnerability?_s_id=cve | vdb-entry |
https://snicco.io/vulnerability-disclosure/breakdance/client-mode-remote-code-execution-breakdance-1-7-0?_s_id=cve | third-party-advisory technical-description |
https://patchstack.com/articles/unpatched-authenticated-rce-in-oxygen-and-breakdance-builder?_s_id=cve | third-party-advisory technical-description |
https://www.youtube.com/watch?v=9glx54-LfRE | exploit |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-31390 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31390 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 22:30:52 | Added to TrackCVE |