Vulnerabilities in FOGProject

17 results
Vexday analysis

FOGProject apresenta 13 vulnerabilidades catalogadas, das quais 3 são críticas, mas nenhuma está sob ataque ativo conhecido. A fraqueza dominante é improper neutralization of special elements (CWE-77), típica de injeção de comandos. Não há atividade recente de divulgação, indicando um panorama de risco estável, embora a presença de falhas críticas demande atenção em ambientes de produção.

CVE-2024-39914CRITICAL FOG has a command injection in /fog/management/export.php?filename=EPSS 23.2%CVE-2025-58443CRITICALFOG's authentication bypass leads to full SQL DB dumpEPSS 18.7%CVE-2024-40645HIGHFOG Authenticated File Upload RCEEPSS 1.0%CVE-2024-42348CRITICALFOG leaks sensitive information (AD domain, username and password)EPSS 0.6%CVE-2024-42349MEDIUMFOG has a Log Information DisclosureEPSS 0.6%CVE-2024-41108HIGHFOG Sensitive Information DisclosureEPSS 0.6%CVE-2023-46237MEDIUMFOG path traversal via unauthenticated endpointEPSS 0.5%CVE-2023-46236HIGHFOG SSRF via unauthenticated endpoint(s)EPSS 0.5%CVE-2026-24138HIGHFOG vulnerable to unauthenticated SSRF via `/fog/service/getversion.php`EPSS 0.4%CVE-2026-47689MEDIUMFOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group Inventory tabEPSS 0.3%CVE-2023-46235MEDIUMFOG stored XSS on log screen via unsanitized request loggingEPSS 0.3%CVE-2024-41954MEDIUMFOG Weak file permissionsEPSS 0.3%CVE-2024-39916MEDIUMNFS server misconfiguration allows file access outside the exported directoryEPSS 0.3%CVE-2026-47687HIGHFOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpointEPSS 0.3%CVE-2026-47685HIGHFOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management pageEPSS 0.2%CVE-2026-47688HIGHFOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedulesEPSS 0.2%CVE-2026-33739MEDIUMFOG has Stored XSS in Multiple Management PagesEPSS 0.2%