go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Wellchoose Administrative Management System - OS Command Injection

TVN ID TVN-202410020
CVE ID CVE-2024-10202
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products Wellchoose Administrative Management System
Description Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
Solution Contact the vendor to install the patch
Credit Xin-Yue Song (CHT Security)
Public Date 2024-10-21
Top