CVE-2024-24215

An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configuration information via a crafted POST request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cellinx:nvt_web_server:5.0.0.014:*:*:*:*:*:*:*

History

15 Feb 2024, 18:08

Type Values Removed Values Added
References () https://github.com/940198871/Vulnerability-details/blob/main/CVE-2024-24215 - () https://github.com/940198871/Vulnerability-details/blob/main/CVE-2024-24215 - Third Party Advisory
References () https://reference3.example.com//1.222.228.4/%2C - () https://reference3.example.com//1.222.228.4/%2C - Broken Link
References () https://reference4.example.com - () https://reference4.example.com - Broken Link
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:cellinx:nvt_web_server:5.0.0.014:*:*:*:*:*:*:*
Summary
  • (es) Un problema en el componente /cgi-bin/GetJsonValue.cgi de Cellinx NVT Web Server 5.0.0.014 permite a los atacantes filtrar información de configuración a través de una solicitud POST manipulada.
First Time Cellinx
Cellinx nvt Web Server
CWE NVD-CWE-noinfo

08 Feb 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-08 19:15

Updated : 2024-02-15 18:08


NVD link : CVE-2024-24215

Mitre link : CVE-2024-24215

CVE.ORG link : CVE-2024-24215


JSON object : View

Products Affected

cellinx

  • nvt_web_server