Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will cause a shell command execution.
This issue affects Phoniebox in all releases through 2.7. Newer 2.x releases were not tested, but they might also be vulnerable.
Phoniebox in version 3.0 and higher are not affected.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-07-10T11:59:23.581Z
Updated: 2024-08-28T18:48:23.868Z
Reserved: 2024-04-15T10:51:29.525Z
Link: CVE-2024-3799
Vulnrichment
Updated: 2024-08-01T20:20:02.008Z
NVD
Status : Awaiting Analysis
Published: 2024-07-10T12:15:10.180
Modified: 2024-11-21T09:30:25.563
Link: CVE-2024-3799
Redhat
No data.