Vulnerability Description
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an arbitrary command and compromise the platform.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gttb | Gtb Central Console | 15.17.1-30814.ng |
Related Weaknesses (CWE)
References
- https://adepts.of0x.cc/gtbcc-pwned/ExploitThird Party Advisory
- https://x-c3ll.github.io/cves.htmlExploit
- https://adepts.of0x.cc/gtbcc-pwned/ExploitThird Party Advisory
- https://x-c3ll.github.io/cves.htmlExploit
FAQ
What is CVE-2024-22107?
CVE-2024-22107 is a vulnerability with a CVSS score of 7.2 (HIGH). An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to comm...
How severe is CVE-2024-22107?
CVE-2024-22107 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22107?
Check the references section above for vendor advisories and patch information. Affected products include: Gttb Gtb Central Console.