CVE-2024-46256

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
27/09/2024
Last modified:
03/06/2025

Description

A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jc21:nginx_proxy_manager:2.11.3:*:*:*:*:*:*:*