Vulnerability intelligence
CVE-2024-23692
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Rejetto HTTP File Server
Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
—
Awaiting FIRST.org data
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
unknown
Federal deadline 2024-07-30
CISA required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2024-07-30.
No linked coverage yet. CyberSIXT tracks this CVE and coverage will appear here.