We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-39914

FOG has a command injection in /fog/management/export.php?filename=



AssignerGitHub_M
Reserved2024-07-02
Published2024-07-12
Updated2024-08-02

Description

FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.



CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

Product status

< 1.5.10.34
affected

References

https://github.com/FOGProject/fogproject/security/advisories/GHSA-7h44-6vq6-cq8j

https://github.com/FOGProject/fogproject/commit/2413bc034753c32799785e9bf08164ccd0a2759f

cve.org CVE-2024-39914

nvd.nist.gov CVE-2024-39914

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.