Description
The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission.
Published: 2024-02-15
Score: 9.8 Critical
EPSS: 2.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update OAKlouds-organization-2.0 to 188 or later version Update OAKlouds-organization-3.0 to 188 or later version Update OAKlouds-webbase-2.0 to 1051 or later version Update OAKlouds-webbase-3.0 to 1051 or later version

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-23536 The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission.
History

Thu, 23 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Hgiga
Hgiga oaklouds-organization-2.0
Hgiga oaklouds-organization-3.0
Hgiga oaklouds-webbase-2.0
Hgiga oaklouds-webbase-3.0
CPEs cpe:2.3:a:hgiga:oaklouds-organization-2.0:*:*:*:*:*:*:*:*
cpe:2.3:a:hgiga:oaklouds-organization-3.0:*:*:*:*:*:*:*:*
cpe:2.3:a:hgiga:oaklouds-webbase-2.0:*:*:*:*:*:*:*:*
cpe:2.3:a:hgiga:oaklouds-webbase-3.0:*:*:*:*:*:*:*:*
Vendors & Products Hgiga
Hgiga oaklouds-organization-2.0
Hgiga oaklouds-organization-3.0
Hgiga oaklouds-webbase-2.0
Hgiga oaklouds-webbase-3.0

Subscriptions

Hgiga Oaklouds-organization-2.0 Oaklouds-organization-3.0 Oaklouds-webbase-2.0 Oaklouds-webbase-3.0
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-21T15:28:01.013Z

Reserved: 2024-02-15T01:33:48.679Z

Link: CVE-2024-26260

cve-icon Vulnrichment

Updated: 2024-08-02T00:07:17.865Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-15T03:15:34.833

Modified: 2025-01-23T19:55:55.470

Link: CVE-2024-26260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses