Remote Code Execution Vulnerability in Inducer's Batch-Issue Exam Tickets Function
CVE-2024-32406

7.5HIGH

Key Information:

Vendor

Inducer

Status
Vendor
CVE Published:
26 April 2024

What is CVE-2024-32406?

The vulnerability in the Relate Learning System prior to version 2024.1 can be exploited by a remote attacker through crafted payloads. This allows the execution of arbitrary code within the Batch-Issue Exam Tickets function, posing significant security risks for users and data integrity. Proper mitigation strategies are essential to safeguard against such attacks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.