CVE-2024-3738

HIGH

nginxwebui < 4.2.4 - Improper Certificate Validation in handlePath Function

Title source: llm
STIX 2.1

Description

A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation of the argument nginxPath leads to improper certificate validation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260577 was assigned to this vulnerability.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.260577
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.260577
Issue Tracking issue-tracking
https://github.com/cym1102/nginxWebUI/issues/138

Scores

CVSS v3 7.3
EPSS 0.0052
EPSS Percentile 39.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (1)
cym1102/nginxwebui < 4.2.4
Published Apr 13, 2024
Tracked Since Feb 18, 2026