Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Twistedknee

#43671of 53,630
6.1Total CVSS
Vulnerabilities · 1
PT-2025-11177
6.1
2025-03-13
Pecanproject · Pecan · CVE-2024-57348
Name of the Vulnerable Software and Affected Versions: PecanProject pecan versions 1.7.2 through 1.8.0 Description: The issue allows a remote attacker to execute arbitrary code via a crafted payload to the `hostname`, `sitegroupid`, `lat`, `lon`, and `sitename` parameters. This enables the attacker to perform unauthorized actions on the affected system. Recommendations: For PecanProject pecan versions 1.7.2 through 1.8.0, consider restricting access to the vulnerable parameters `hostname`, `sitegroupid`, `lat`, `lon`, and `sitename` to minimize the risk of exploitation until a patch is available. Avoid using these parameters in crafted payloads to prevent arbitrary code execution.