All CVEs
Vulnerability intelligence

CVE-2024-23692

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Rejetto HTTP File Server

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
—
Awaiting FIRST.org data
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
unknown
Federal deadline 2024-07-30
CISA required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2024-07-30.

NVD entry PoC / advisory CISA KEV

No linked coverage yet. CyberSIXT tracks this CVE and coverage will appear here.

Related CVEs — Rejetto