CVE-2024-1577
Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP software versions through 5.11.2.
- CVSS 4.0
- 9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.13% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- megabip/megabip
- Source
- cvd@cert.pl
References
- https://cert.pl/en/posts/2024/06/CVE-2024-1576/Third Party Advisory
- https://cert.pl/posts/2024/06/CVE-2024-1576/Third Party Advisory
- https://megabip.pl/Product
- https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznejPress/Media Coverage
- https://cert.pl/en/posts/2024/06/CVE-2024-1576/Third Party Advisory
- https://cert.pl/posts/2024/06/CVE-2024-1576/Third Party Advisory
- https://megabip.pl/Product
- https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznejPress/Media Coverage
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.