Template Engine Vulnerability in Supsystic Popup Product by Supsystic
CVE-2024-52434

9.1CRITICAL

Key Information:

Vendor

Supsystic

Vendor
CVE Published:
18 November 2024

What is CVE-2024-52434?

A vulnerability exists in the template engine of the Popup by Supsystic plugin that allows for improper neutralization of special elements, enabling potential command injection. Specifically, this issue affects versions of Popup by Supsystic from n/a through 1.10.29. Exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the server, which poses serious risks to system integrity and confidentiality.

Affected Version(s)

Popup by Supsystic 0 <= 1.10.29

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.