Nginx-UI arbitrary file write through the Import Certificate feature
CVE-2024-23827
9.8CRITICAL
What is CVE-2024-23827?
The vulnerability in Nginx-UI arises from the Import Certificate feature, which inadequately validates user input, allowing it to write to arbitrary file paths on the system. This weakness could enable an attacker to execute remote code by overwriting critical configuration files, such as app.ini. The issue has been addressed in version 2.0.0.beta.12.
Affected Version(s)
nginx-ui < 2.0.0.beta.12
