github.com
https://github.com/dos-m0nk3y/CVE/tree/main/CVE-2024-48573 CVE-2024-48573
CRITICAL
AquilaCMS 1.409.20 - Remote Command Execution (RCE)
Record summary
CVE-2024-48573 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 30, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | 1.409.20 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBAquilaCMS 1.409.20 - Remote Command Execution (RCE)ExploitDB exploitby Eui Chul ChungNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-48573