CVE-2024-28048
Last modified
CVE-2024-28048 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was unreachable, therefore, users should consider stop using ffBull ver.4.11.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.
Description
OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was unreachable, therefore, users should consider stop using ffBull ver.4.11.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-28048?
How severe is CVE-2024-28048?
How do I fix CVE-2024-28048?
Are you affected by CVE-2024-28048?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
