• caglararli@hotmail.com
  • 05386281520

CVE-2024-9324 | Intelbras InControl up to 2.21.57 Relatório de Operadores Page /v1/operador/ fields code injection

Çağlar Arlı      -    11 Views

CVE-2024-9324 | Intelbras InControl up to 2.21.57 Relatório de Operadores Page /v1/operador/ fields code injection

A vulnerability was found in Intelbras InControl up to 2.21.57. It has been rated as critical. Affected by this issue is some unknown functionality of the file /v1/operador/ of the component Relatório de Operadores Page. The manipulation of the argument fields leads to code injection. This vulnerability is handled as CVE-2024-9324. The attack may be launched remotely. Furthermore, there is an exploit available. The vendor was informed early on 2024-07-19 about this issue. The release of a fixed version 2.21.58 was announced for the end of August 2024 but then was postponed until 2024-09-20.