CVE-2024-2448

An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.
Configurations

No configuration.

History

21 Nov 2024, 09:09

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad de inyección de comandos del sistema operativo en LoadMaster. Un usuario de UI autenticado con cualquier configuración de permisos puede inyectar comandos en un componente de UI usando un comando de shell, lo que resulta en la inyección de comandos del sistema operativo.
References () https://progress.com/loadmaster - () https://progress.com/loadmaster -
References () https://support.kemptechnologies.com/hc/en-us/articles/25119767150477-LoadMaster-Security-Vulnerabilities-CVE-2024-2448-and-CVE-2024-2449 - () https://support.kemptechnologies.com/hc/en-us/articles/25119767150477-LoadMaster-Security-Vulnerabilities-CVE-2024-2448-and-CVE-2024-2449 -

22 Mar 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-22 14:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2448

Mitre link : CVE-2024-2448

CVE.ORG link : CVE-2024-2448


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')