Vulnerability Description
: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://patchstack.com/articles/unpatched-authenticated-rce-in-oxygen-and-breakd
- https://patchstack.com/database/vulnerability/breakdance/wordpress-breakdance-pl
- https://snicco.io/vulnerability-disclosure/breakdance/client-mode-remote-code-ex
- https://www.youtube.com/watch?v=9glx54-LfRE
- https://patchstack.com/articles/unpatched-authenticated-rce-in-oxygen-and-breakd
- https://patchstack.com/database/vulnerability/breakdance/wordpress-breakdance-pl
- https://snicco.io/vulnerability-disclosure/breakdance/client-mode-remote-code-ex
- https://www.youtube.com/watch?v=9glx54-LfRE
FAQ
What is CVE-2024-31390?
CVE-2024-31390 is a vulnerability with a CVSS score of 9.9 (CRITICAL). : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.
How severe is CVE-2024-31390?
CVE-2024-31390 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-31390?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.