Zurück zur CVE-Übersicht
CVE-2024-28386
CRITICAL(9.8)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Risk Signal Score25/100 — MITTEL
- CVSS 9.8 — Kritisch
EPSS-Score
1%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
Beschreibung
An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.
Referenzen
- http://home-madeio.com
- https://reference1.example.com/modules/fastmagsync/crons/cron_mutualise_job_queu...
- https://security.friendsofpresta.org/modules/2024/03/19/fastmagsync.html
- https://www.home-made.io/module-fastmag-sync-prestashop/
- http://fastmagsync.com
- http://home-madeio.com
- https://reference1.example.com/modules/fastmagsync/crons/cron_mutualise_job_queu...
- https://security.friendsofpresta.org/modules/2024/03/19/fastmagsync.html
- https://www.home-made.io/module-fastmag-sync-prestashop/