An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the URL.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://l3v3lforall.github.io/EpointWebBuilder_v5.x_VULN/ |
|
History
Thu, 27 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Epoint
Epoint epointwebbuilder |
|
| CPEs | cpe:2.3:a:epoint:epointwebbuilder:5.1.0:sp1:*:*:*:*:*:* cpe:2.3:a:epoint:epointwebbuilder:5.2.1:sp1:*:*:*:*:*:* cpe:2.3:a:epoint:epointwebbuilder:5.4.1:-:*:*:*:*:*:* cpe:2.3:a:epoint:epointwebbuilder:5.4.2:-:*:*:*:*:*:* |
|
| Vendors & Products |
Epoint
Epoint epointwebbuilder |
Thu, 29 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-233 CWE-94 |
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-29T18:32:53.308Z
Reserved: 2024-01-25T00:00:00
Link: CVE-2024-24525
Updated: 2024-08-01T23:19:52.650Z
Status : Analyzed
Published: 2024-02-29T06:15:47.427
Modified: 2025-03-27T16:22:33.540
Link: CVE-2024-24525
No data.
OpenCVE Enrichment
No data.