CVE-2024-4748
Estado: ModificadaAlta (7.8)—
The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server. The exploitation risk is limited since CRUDDIY is meant to be launched locally. Nevertheless, a user with the project running on their computer might visit a website which would send such a malicious request to the locally launched server.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.11%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-78
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-4748",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-4748",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-06-25T14:02:18.641194Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cvd@cert.pl",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cvd@cert.pl",
"affectedData": [
{
"repo": "https://github.com/jan-vandenberg/cruddiy",
"vendor": "CRUDDIY",
"product": "CRUDDIY",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "202312.1"
}
],
"defaultStatus": "unknown"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:cruddiy:cruddiy:*:*:*:*:*:*:*:*"
],
"vendor": "cruddiy",
"product": "cruddiy",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "202312.1"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-06-24T14:15:13.030",
"references": [
{
"url": "https://cert.pl/en/posts/2024/06/CVE-2024-4748",
"tags": [
"Third Party Advisory"
],
"source": "cvd@cert.pl"
},
{
"url": "https://cert.pl/posts/2024/06/CVE-2024-4748",
"tags": [
"Third Party Advisory"
],
"source": "cvd@cert.pl"
},
{
"url": "https://github.com/jan-vandenberg/cruddiy/issues/67",
"tags": [
"Issue Tracking"
],
"source": "cvd@cert.pl"
},
{
"url": "https://cert.pl/en/posts/2024/06/CVE-2024-4748",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cert.pl/posts/2024/06/CVE-2024-4748",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/jan-vandenberg/cruddiy/issues/67",
"tags": [
"Issue Tracking"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cvd@cert.pl",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server. \nThe exploitation risk is limited since CRUDDIY is meant to be launched locally. Nevertheless, a user with the project running on their computer might visit a website which would send such a malicious request to the locally launched server."
},
{
"lang": "es",
"value": "El proyecto CRUDDIY es vulnerable a la inyección de comandos de shell mediante el envío de una solicitud POST manipulada al servidor de aplicaciones. El riesgo de explotación es limitado ya que CRUDDIY debe lanzarse localmente. Sin embargo, un usuario con el proyecto ejecutándose en su computadora podría visitar un sitio web que enviaría una solicitud maliciosa al servidor iniciado localmente."
}
],
"lastModified": "2026-06-17T08:02:33.057",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:j11g:cruddiy:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5908333-F478-4071-A90D-BEC428110174",
"versionEndIncluding": "202312.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cvd@cert.pl"
}