CVE-2024-1297

HIGH

Loomio <2.22.0 - Command Injection

Title source: llm
STIX 2.1

Description

Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.

Scores

CVSS v3 7.2
EPSS 0.0151
EPSS Percentile 81.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
loomio/loomio 2.22.0
Loomio/Loomio 2.22.0
Published Feb 20, 2024
Tracked Since Feb 18, 2026