CVE-2024-28397
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 4.5% (91th percentile)
- Weakness
- CWE-94
- NVD status
- Deferred
- Published
- 2024-06-20
CVE-2024-28397 at NVD
22 known exploits for CVE-2024-28397
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for CVE-2024-28397
Js2Py 0.74 - RCE
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
π js2py 0.74 Automated Sandbox Escape / Code Execution
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397
Pyload Remote Code Execution Exploit
Pyload Remote Code Execution
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
Exploit for CVE-2024-39205
Exploit for CVE-2024-28397
Exploit for CVE-2024-28397