CVE-2024-35374

CRITICAL LAB

Mocodo Online < 4.2.6 - Remote Code Execution via SQL Case Input Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-35374. PoCs published by Rikoot.

AI-analyzed exploit summary This repository contains a functional Metasploit module for CVE-2024-35374, which exploits an improper sanitization vulnerability in Mocodo Online's /web/generate.php endpoint to achieve remote code execution. The exploit sends a crafted POST request with a malicious payload in the 'sql_case' parameter.

Description

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

Exploits (1)

nomisec WORKING POC 1 stars
by Rikoot · poc
https://github.com/Rikoot/CVE-2024-35374

This repository contains a functional Metasploit module for CVE-2024-35374, which exploits an improper sanitization vulnerability in Mocodo Online's /web/generate.php endpoint to achieve remote code execution. The exploit sends a crafted POST request with a malicious payload in the 'sql_case' parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mocodo Online 4.2.6 and below
No auth needed
Prerequisites: Network access to the target web application · Metasploit Framework for execution
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0837
EPSS Percentile 92.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Lab Environment

COMMUNITY
Community Lab
docker pull trafex/php-nginx:latest

Details

CWE
CWE-77
Status published
Products (2)
mocodo/mocodo_online < 4.2.6
pypi/mocodo 0 - 4.2.7PyPI
Published May 24, 2024
Tracked Since Feb 18, 2026