PT-2024-35773 · Anji Plus · Anji-Plus Aj-Report

Published

2024-05-26

·

Updated

2025-03-01

·

CVE-2024-5355

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions anji-plus AJ-Report versions up to 1.4.1
Description A critical issue has been found in the affected software, affecting the IGroovyHandler function. This issue leads to command injection and can be initiated remotely. The exploit has been disclosed to the public.
Recommendations For anji-plus AJ-Report versions up to 1.4.1, consider disabling the IGroovyHandler function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-5355

Affected Products

Anji-Plus Aj-Report