CVE-2024-39935
July 4, 2024, 9:15 p.m.
None
No Score
Description
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5.
Product(s) Impacted
Product | Versions |
---|---|
NGINX Proxy Manager |
|
Weaknesses
Tags
Date
- Published: July 4, 2024, 9:15 p.m.
- Last Modified: July 4, 2024, 9:15 p.m.
Status : Received
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
cve@mitre.org
*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.