CVE-2024-41308
HIGHenjay_crm 1.0 - Improper Access Control via Ping Feature
Title source: llmDescription
An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.
References (1)
Core 1
Core References
Scores
CVSS v3
7.8
EPSS
0.0021
EPSS Percentile
10.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-284
Status
published
Products (1)
enjayworld/enjay_crm
1.0
Published
Aug 07, 2024
Tracked Since
Feb 18, 2026