CVE-2024-7728 HIGH

CVE-2024-7728: CAYIN Technology CMS - OS Command Injection

Vendor Cayin Technology
Product CMS-SE(22.04)
Weakness CWE-78
Published August 14, 2024
Last update August 14, 2024

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.

Key dates

02Disclosure timeline

August 14, 2024 CVE published
August 14, 2024 Record updated