PT-2024-37932 · Journyx · Journyx

Jaggar Henry

·

Published

2024-08-07

·

Updated

2024-08-12

·

CVE-2024-6891

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow. This issue allows for the injection of malicious python code, potentially leading to unauthorized access or control.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Eval Injection

Weakness Enumeration

Related Identifiers

CVE-2024-6891

Affected Products

Journyx