Sploitus

CVE-2024-49368

1 known exploit for CVE-2024-49368

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.

Affected products
Nginx-Ui
Nginxui Nginx Ui
≤ 1.9.9-4, 2.0.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
27.7% (98th percentile)
Weakness
CWE-20
NVD status
Analyzed
Published
2024-10-21
CVE-2024-49368 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-49368

Proof-of-concept code and exploit modules indexed by Sploitus