Vulnerability Description
QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp folder.is shipped with the product.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://synacktiv.com/en/advisories/jpgraph-professional-version-pre-authenticat
- https://www.synacktiv.com/advisories/jpgraph-professional-version-pre-authentica
FAQ
What is CVE-2024-39165?
CVE-2024-39165 is a vulnerability with a CVSS score of 9.8 (CRITICAL). QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name i...
How severe is CVE-2024-39165?
CVE-2024-39165 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-39165?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.