Back

HIGH

CAYIN Technology CMS - OS Command Injection

Published Aug 14, 2024

Description

The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.

Affected products

Remediation

Vendor solution

For CMS-SE(22.04) v11.0, install patch P23005 or later. For CMS-SE(18.04) v11.0, install patch P23006 or later. For CMS-SE v11.0, Install patch P23007 or later.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Aug 14, 2024
Updated Aug 14, 2024
Reserved Aug 13, 2024
CISA Vulnrichment
Updated Aug 14, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner twcert
Published Aug 14, 2024
Updated Aug 14, 2024
Exploited since n/a
EUVD-2024-48605