OS Command Injection Vulnerability Affects N-Reporter and N-Cloud Products
CVE-2024-4301

8.8HIGH

Key Information:

Vendor

N-Partner

Vendor
CVE Published:
29 April 2024

What is CVE-2024-4301?

An OS Command Injection vulnerability exists in N-Reporter and N-Cloud products by N-Partner, allowing remote attackers with normal user privileges to execute arbitrary system commands. This can be achieved by manipulating user inputs on specific pages, posing a significant risk to system integrity and data security. Prompt remediation is essential to mitigate potential exploitation.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.