TROYANOSYVIRUS
Back to CVEs

CVE-2024-26260

CRITICAL
9.8

Description

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published2/15/2024
Last Modified1/23/2025
Sourcenvd
Honeypot Sightings0

Affected Products

hgiga:oaklouds-organization-2.0hgiga:oaklouds-organization-3.0hgiga:oaklouds-webbase-2.0hgiga:oaklouds-webbase-3.0

Weaknesses (CWE)

CWE-78

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.