CVE-2024-39914

Published Jul 12, 2024

Last updated a year ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-39914 is a command injection vulnerability affecting FOG, a cloning/imaging/rescue suite/inventory management system. Specifically, versions prior to 1.5.10.34 are vulnerable. The vulnerability exists in the `packages/web/lib/fog/reportmaker.class.php` file, where the `filename` parameter to `/fog/management/export.php` is susceptible to command injection. This vulnerability allows attackers to inject arbitrary system commands by manipulating the `filename` parameter. Successful exploitation could lead to the execution of arbitrary system commands or the deployment of persistent webshells. The vulnerability has been fixed in version 1.5.10.34.

Description
FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.
Source
security-advisories@github.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-77

Social media

Hype score
Not currently trending