CVE-2024-1577

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
12/06/2024
Last modified:
14/08/2024

Description

Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP software versions through 5.11.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:megabip:megabip:*:*:*:*:*:*:*:* 5.11.2 (including)