Advisory ID: LVD-2024-014
CVSSv 4.0 Vector: AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVSSv 4.0 Base Score: 7.5
Severity: High
CVE: CVE Reserved
CWE: CWE-77
Date Published: 2024-10-15
Description:
Authenticated users can inject payloads while creating Universal Normalizer, which gets executed leading to Remote Code Execution.
Affected Product:
Universal Normalizer v5.6.0.
Solution:
Upgrade to Universal Normalizer v5.7.0.
Acknowledgments:
Mehmet D. Ince
Sr. Vulnerability Researcher
Comments
Article is closed for comments.