Loomio version 2.22.0 allows executing arbitrary commands on the server.
This is possible because the application is vulnerable to OS Command Injection.
This is possible because the application is vulnerable to OS Command Injection.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 31 Dec 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Loomio
Loomio loomio |
|
Weaknesses | CWE-78 | |
CPEs | cpe:2.3:a:loomio:loomio:2.22.0:*:*:*:*:*:*:* | |
Vendors & Products |
Loomio
Loomio loomio |

Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2024-08-28T19:46:53.377Z
Reserved: 2024-02-06T21:45:03.994Z
Link: CVE-2024-1297

Updated: 2024-08-01T18:33:25.342Z

Status : Analyzed
Published: 2024-02-20T00:15:14.463
Modified: 2024-12-31T14:28:27.090
Link: CVE-2024-1297

No data.

No data.