CVE-2024-10202

HIGH

Administrative Management System - Command Injection

Title source: llm
STIX 2.1

Description

Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-8162-dc491-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-8163-b701e-2.html

Scores

CVSS v3 8.8
EPSS 0.0106
EPSS Percentile 60.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
wellchoose/administrative_management_system
Published Oct 21, 2024
Tracked Since Feb 18, 2026