CVE-2024-36622

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
29/11/2024
Last modified:
02/07/2025

Description

In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:raspap:raspap-webgui:*:*:*:*:*:*:*:* 3.0.9 (including)