CVE-2024-27114

Sept. 11, 2024, 4:26 p.m.

Undergoing Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

SO Planning

  • <= 1.52.02

Source

csirt@divd.nl

Tags

CVE-2024-27114 details

Published : Sept. 11, 2024, 2:15 p.m.
Last Modified : Sept. 11, 2024, 4:26 p.m.

Description

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.

References

URL Source
https://csirt.divd.nl/CVE-2024-27114 csirt@divd.nl
This website uses the NVD API, but is not approved or certified by it.