CVE Vulnerabilities

CVE-2024-37779

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

Published: Sep 23, 2024 | Modified: Sep 27, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.

Weakness

The product does not adequately filter user-controlled input for special elements with control implications.

Potential Mitigations

References