CVE-2024-35374

Published May 24, 2024

Last updated 3 months ago

CVSS critical 9.8
Mocodo Online

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-35374 affects Mocodo Online version 4.2.6 and below. The vulnerability stems from improper sanitization of the `sql_case` input field in `/web/generate.php`. This lack of sanitization allows remote attackers to execute arbitrary commands. This can potentially lead to command injection and ultimately remote code execution (RCE) under certain conditions.

Description
Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.
Source
cve@mitre.org
NVD status
Analyzed
Products
mocodo_online

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-77

Social media

Hype score
Not currently trending

Configurations