CVE-2024-4748
CVSS V2 None
CVSS V3 None
Description
The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server.
The exploitation risk is limited since CRUDDIY is meant to be launched locally. Nevertheless, a user with the project running on their computer might visit a website which would send such a malicious request to the locally launched server.
Overview
- CVE ID
- CVE-2024-4748
- Assigner
- CERT-PL
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-06-24T13:52:12.451Z
- Last Modified Date
- 2024-06-24T13:52:12.451Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://cert.pl/en/posts/2024/06/CVE-2024-4748 | third-party-advisory |
https://cert.pl/posts/2024/06/CVE-2024-4748 | third-party-advisory |
https://github.com/jan-vandenberg/cruddiy/issues/67 | issue-tracking |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-4748 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4748 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 16:56:18 | Added to TrackCVE |