CVE-2024-7728 Information

Description

The specific CGI of the CAYIN Technology CMS does not properly validate user input allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.

Reference

https://www.twcert.org.tw/en/cp-139-8002-b6167-2.html https://www.twcert.org.tw/tw/cp-132-8001-8416d-1.html https://resource1.cayintech.com/patch/

Share on: