PT-2024-36021 · Rhinos · Rhinos

Rafael Pedrero

·

Published

2024-05-27

·

Updated

2025-06-05

·

CVE-2024-5407

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: RhinOS versions 3.0-1190
Description: A vulnerability could allow PHP code injection through the "search" parameter in /portal/search.htm, enabling a remote attacker to perform a reverse shell on the remote system and compromise the entire infrastructure.
Recommendations: For RhinOS versions 3.0-1190, avoid using the search parameter in the /portal/search.htm endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the /portal/search.htm endpoint to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-5407

Affected Products

Rhinos