CVE Vulnerabilities

CVE-2024-7059

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Published: Nov 05, 2024 | Modified: Nov 09, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line.

Weakness

The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Potential Mitigations

References