PT-2024-36532 · Unknown · Avenwu Whistle

Paul Gerste

·

Published

2024-12-10

·

Updated

2024-12-11

·

CVE-2024-55500

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avenwu Whistle versions 2.9.90 and earlier
Description The issue allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on the victim's machine. This is due to a Cross-Site Request Forgery (CSRF) flaw.
Recommendations For Avenwu Whistle versions 2.9.90 and earlier, update to a version that fixes the CSRF issue to prevent malicious API calls and arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-55500
GHSA-GG6X-448Q-PQQM

Affected Products

Avenwu Whistle