CVE-2024-28033
Last modified
CVE-2024-28033 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was unreachable, therefore, users should consider stop using WebProxy 1.7.8 and 1.7.9.. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was unreachable, therefore, users should consider stop using WebProxy 1.7.8 and 1.7.9.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-28033?
How severe is CVE-2024-28033?
How do I fix CVE-2024-28033?
Are you affected by CVE-2024-28033?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
