← back
CVE-2024-1577

Remote Code Execution in MegaBIP

CVSS 9.3 CRITICALEPSS 1.1%CWE-94
Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP software versions through 5.11.2.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/R:I/V:D/RE:M/U:Amber
Affected products
Jan Syski · MegaBIP

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →