CVE-2024-48359
CRITICALQualitor v8.24 - Remote Code Execution via gridValoresPopHidden Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-48359. PoCs published by OpenXP-Research.
AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2024-48359, an unauthenticated remote code execution vulnerability in Qualitor <= v8.24. The exploit leverages command injection via the `processVariavel.php` endpoint, bypassing a previous fix for CVE-2023-47253.
Description
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.
Exploits (1)
This repository contains a proof-of-concept for CVE-2024-48359, an unauthenticated remote code execution vulnerability in Qualitor <= v8.24. The exploit leverages command injection via the `processVariavel.php` endpoint, bypassing a previous fix for CVE-2023-47253.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H