Sploitus

CVE-2024-27179

1 known exploit for CVE-2024-27179

Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. As for the affected products/models/versions, see the reference URL.

CVSS 3.1
4.7 MEDIUM
EPSS
0.3% (17th percentile)
Weakness
CWE-1295
NVD status
Deferred
Published
2024-06-14
Attack patterns
CAPEC-37
Entry point
formSubmitCompleteEventHandler request body
Path
contentwebserver/upload

Fix

This issue is fixed in the version released on June 14, 2024 and all later versions.

CVE-2024-27179 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-27179

Proof-of-concept code and exploit modules indexed by Sploitus