Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges account in order to abuse this functionality and execute malicious code, load DLL libraries and executing OS commands on a host system with applications high privileges.
This issue has been fixed in versionĀ 8.0.00204.0
Metrics
Affected Vendors & Products
References
History
Fri, 21 Feb 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Feb 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges account in order to abuse this functionality and execute malicious code, load DLL libraries and executing OS commands on a host system with applications high privileges. This issue has been fixed in versionĀ 8.0.00204.0 | |
| Title | Code Injection in Wyn Enterprise | |
| Weaknesses | CWE-1336 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-02-21T11:40:00.281Z
Updated: 2025-02-21T13:14:07.800Z
Reserved: 2024-09-24T14:09:28.319Z
Link: CVE-2024-9150
Updated: 2025-02-21T13:13:57.914Z
Status : Received
Published: 2025-02-21T12:15:30.463
Modified: 2025-02-21T12:15:30.463
Link: CVE-2024-9150
No data.