CVE-2024-52959 Information
Nov 28, 2024
cve
Description
A Improper Control of Generation of Code (‘Code Injection’) vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.
Reference
https://zuso.ai/advisory/za-2024-12
Share on: