A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 03 Oct 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nginxproxymanager
Nginxproxymanager nginx Proxy Manager |
|
Weaknesses | CWE-77 | |
CPEs | cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:2.11.3:*:*:*:*:*:*:* | |
Vendors & Products |
Nginxproxymanager
Nginxproxymanager nginx Proxy Manager |
|
Metrics |
cvssV3_1
|
Fri, 27 Sep 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-27T00:00:00
Updated: 2024-10-24T17:12:15.730807
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46256
Vulnrichment
Updated: 2024-10-03T17:33:54.843Z
NVD
Status : Awaiting Analysis
Published: 2024-09-27T18:15:05.787
Modified: 2024-10-24T17:15:16.690
Link: CVE-2024-46256
Redhat
No data.