A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Jan 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Firebearstudio
Firebearstudio improved Import \& Export |
|
Weaknesses | CWE-91 | |
CPEs | cpe:2.3:a:firebearstudio:improved_import_\&_export:3.8.6:*:*:*:*:magento:*:* | |
Vendors & Products |
Firebearstudio
Firebearstudio improved Import \& Export |
|
Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 06 Aug 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-02-16T00:00:00
Updated: 2024-08-06T15:46:20.127Z
Reserved: 2024-02-07T00:00:00
Link: CVE-2024-25413
Vulnrichment
Updated: 2024-08-01T23:44:08.648Z
NVD
Status : Analyzed
Published: 2024-02-16T02:15:51.307
Modified: 2025-01-13T14:34:23.363
Link: CVE-2024-25413
Redhat
No data.