CVE-2024-5407
CVE-2024-5407 allows for PHP code injection in RhinOS 3.0-1190, specifically via the "search" parameter in /portal/search.htm. This vulnerability could enable a remote attacker to execute a reverse shell, potentially leading to full infrastructure compromise. Although the CVSS score is 0, indicating a low base score, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a moderate risk despite not being immediately critical. The vulnerability is tagged as "In The Wild," indicating that it's actively being exploited. Successful exploitation could grant attackers complete control over the affected system, posing a significant threat to data confidentiality, integrity, and availability. Immediate patching is advised if evidence of exploitation is detected.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.