PT-2024-15795 · Mldong · Mldong
Biantaibao
·
Published
2024-01-19
·
Updated
2024-05-17
·
CVE-2024-0738
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
mldong version 1.0
Description
A critical issue has been found in mldong, affecting the
ExpressionEngine function of the file com/mldong/modules/wf/engine/model/DecisionModel.java. This issue leads to code injection and can be initiated remotely. The exploit has been disclosed to the public.Recommendations
For version 1.0, consider disabling the
ExpressionEngine function until a patch is available to prevent code injection attacks. Restrict access to the com/mldong/modules/wf/engine/model/DecisionModel.java file to minimize the risk of exploitation. Avoid using the DecisionModel.java file in remote operations until the issue is resolved.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mldong