CVE-2024-21855

CRITICAL

GoCast 1.1.3 - Unauthenticated Remote Code Execution via HTTP API

Title source: llm
STIX 2.1

Description

A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

Scores

CVSS v3 9.8
EPSS 0.0204
EPSS Percentile 78.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
mayuresh82/gocast 1.1.3
Published Nov 21, 2024
Tracked Since Feb 18, 2026