PT-2024-15795 · Mldong · Mldong

·

CVE-2024-0738

·

Published

2024-01-19

·

Updated

2024-05-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mldong version 1.0
Description A critical issue has been found in mldong, affecting the ExpressionEngine function of the file com/mldong/modules/wf/engine/model/DecisionModel.java. This issue leads to code injection and can be initiated remotely. The exploit has been disclosed to the public.
Recommendations For version 1.0, consider disabling the ExpressionEngine function until a patch is available to prevent code injection attacks. Restrict access to the com/mldong/modules/wf/engine/model/DecisionModel.java file to minimize the risk of exploitation. Avoid using the DecisionModel.java file in remote operations until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-0738

Affected Products

Mldong