CVE-2024-30845

MEDIUM

Rainbow external link network disk 5.5 - Remote Code Execution via Input Parameter Validation Component

Title source: llm
STIX 2.1

Description

Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote attacker to execute arbitrary code via the validation component of the input parameters.

Scores

CVSS v3 6.1
EPSS 0.0064
EPSS Percentile 46.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (1)
rainbow_external_link_network_disk_project/rainbow_external_link_network_disk 5.5
Published Apr 12, 2024
Tracked Since Feb 18, 2026