CVE-2024-49366
Nginxui
CVE-2024-49366 is a critical vulnerability in Nginx UI, a web interface for Nginx servers, allowing arbitrary file writes due to improper input validation. Versions up to v2.0.0-beta.35 are affected. This path traversal vulnerability (CWE-22) enables attackers to write files outside the intended directory, potentially leading to privilege escalation and system compromise. Although the CVSS score is 7.5, the SVRS of 68 suggests that while not critical, this should be addressed swiftly. The vulnerability has been observed "In The Wild", increasing the risk. Upgrade to version 2.0.0-beta.26 or later to mitigate this risk, preventing unauthorized file system access and maintaining server security. This CVE is significant because it could enable a full system takeover.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.