CVE-2024-52958

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
27/11/2024
Last modified:
06/03/2026

Description

A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gss:iota_c.ai:*:*:*:*:*:*:*:* 1.0.0 (including) 2.1.3 (including)


References to Advisories, Solutions, and Tools