← Back

CVE-2024-24386

nvd nist
Published: Feb 15, 2024Modified: Sep 18, 2025

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.

Affected (40)

Products: Vitalpbx: Vitalpbx
1 product
Vitalpbx
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Vitalpbx
Version 3.0.4-2
Version 3.0.4-4
Version 3.0.4
Version 3.0.6-1
Version 3.0.6-2
Version 3.0.8
Version 3.0.8 r2
Version 3.0.8 r3
Version 3.0.9 r3
Version 3.0.9 r5
Version 3.1.0
Version 3.1.1
Version 3.1.1 r2
Version 3.1.1 r3
Version 3.1.2 r1
Version 3.1.3 r1
Version 3.1.4 r1
Version 3.1.4 r2
Version 3.1.5 r1
Version 3.1.5 r2
Version 3.1.5 r3
Version 3.1.5 r4
Version 3.1.6 r1
Version 3.1.7 r1
Version 3.2.1
Version 3.2.2 r1
Version 3.2.3 r1
Version 3.2.3 r2
Version 3.2.3 r4
Version 3.2.3 r5
Version 3.2.3 r6
Version 3.2.3 r7
Version 3.2.3 r8
Version 3.2.3 r9
Version 3.2.4 r1
Version 3.2.4 r2
Version 3.2.4 r4
Version 3.2.4 r5
Version 3.2.4 r6
Version 3.2.5 r1

References (4)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.