CVE-2024-50715
CVE-2024-50715: Command Injection Vulnerability in Smart Agent v.1.1.0. A remote attacker can exploit a flaw in the /youtubeInfo.php component of smarts-srl.com's Smart Agent to obtain sensitive information. The vulnerability stems from an unsanitized parameter, leading to potential command injection. While the CVSS score is 0, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a low to moderate risk that should still be addressed. This command injection could allow unauthorized access to system data and potentially lead to further compromise. Organizations using Smart Agent v.1.1.0 should investigate and patch or mitigate this security risk promptly to prevent potential data breaches or system exploitation. While not critical (SVRS below 80), its presence "In The Wild" suggests active exploitation attempts may be occurring.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.