PT-2024-28728 · Fog · Fog

0Xbad53C

+2

·

Published

2024-07-12

·

Updated

2025-09-29

·

CVE-2024-39914

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FOG versions prior to 1.5.10.34
Description The issue is related to a command injection via the filename parameter to the "/fog/management/export.php" API endpoint. This allows for code execution. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For versions prior to 1.5.10.34, update to version 1.5.10.34 to resolve the issue. As a temporary workaround, consider restricting access to the "/fog/management/export.php" API endpoint to minimize the risk of exploitation. Avoid using the filename parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-39914
GHSA-7H44-6VQ6-CQ8J

Affected Products

Fog