github.comexploit
https://github.com/jxp98/VulResearch/blob/main/2024/12/1.Datax-Web%20-%20Remote%20Code%20Execution.md CVE-2024-12358
MEDIUM
WeiYe-Jing datax-web add os command injection
Record summary
CVE-2024-12358 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 9, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
datax-webBrowse WeiYe-Jing / datax-webDefault status: unknown | CVE List | 2.1.1 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-12358 VDB-287277 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.287277 VDB-287277 | WeiYe-Jing datax-web add os command injectionvdb entryTechnical description
https://vuldb.com/?id.287277 Submit #457865 | https://github.com/WeiYe-Jing/ https://github.com/WeiYe-Jing/datax-web 2.1.1 OS Command InjectionThird-party advisory
https://vuldb.com/?submit.457865