The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-02-15T02:18:34.668Z

Updated: 2024-08-21T15:28:01.013Z

Reserved: 2024-02-15T01:33:48.679Z

Link: CVE-2024-26260

cve-icon Vulnrichment

Updated: 2024-08-02T00:07:17.865Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-15T03:15:34.833

Modified: 2024-06-28T02:15:03.190

Link: CVE-2024-26260

cve-icon Redhat

No data.