Sploitus

CVE-2024-32651

8 known exploits for CVE-2024-32651

changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).

Affected products
Jinja2, Changedetection.Io
CVSS 3.1
10.0 CRITICAL
EPSS
83.6% (100th percentile)
Weakness
CWE-1336
NVD status
Deferred
Published
2024-04-25
CVE-2024-32651 at NVD
Authoritative description, scoring and affected products

8 known exploits for CVE-2024-32651

Proof-of-concept code and exploit modules indexed by Sploitus