An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.
References
Configurations
No configuration.
History
21 Nov 2024, 08:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://erickduarte.notion.site/VitalPBX-3-2-4-5-ee402173241c493687aa22ec60160c67?pvs=4 - | |
References | () https://github.com/erick-duarte/CVE-2024-24386 - |
19 Aug 2024, 21:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
15 Feb 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-15 08:15
Updated : 2024-11-21 08:59
NVD link : CVE-2024-24386
Mitre link : CVE-2024-24386
CVE.ORG link : CVE-2024-24386
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control