CVE-2024-2448
An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.
- Affected products
- Loadmaster
- Progress Loadmaster
- < 7.2.54.9, 7.2.59.3, 7.1.35.10, 7.2.48.10
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 55.1% (99th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2024-03-22
- Attack patterns
- CAPEC-88, CAPEC-113
CVE-2024-2448 at NVD
1 known exploit for CVE-2024-2448
Proof-of-concept code and exploit modules indexed by Sploitus