vendor:
AquilaCMS
by:
Eui Chul Chung
6.1
CVSS
HIGH
Remote Command Execution (RCE)
RCE
CWE
Product Name: AquilaCMS
Affected Version From: 1.409.20
Affected Version To: 1.409.20
Patch Exists: NO
Related CWE: CVE-2024-48572, CVE-2024-48573
CPE: a:aquilacms_project:aquilacms:1.409.20
Platforms Tested:
2024
AquilaCMS 1.409.20 – Remote Command Execution (RCE)
AquilaCMS 1.409.20 is prone to Remote Command Execution (RCE) due to improper input validation. An attacker can exploit this vulnerability to execute arbitrary commands remotely. This exploit has been assigned CVE-2024-48572 and CVE-2024-48573.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user inputs properly to prevent command injection attacks. Additionally, restricting access to the affected functionality can help reduce the attack surface.