CVE-2024-28394: Critical severity Advanced Plugins reportsstatistics vulnerability
Published Mar 19, 2024
·Updated
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.
Affected Software
1 affected component
Advanced Plugins reportsstatistics<1.3.20
Event History
Mar 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28394?
CVE-2024-28394 has a high severity level due to the potential for arbitrary code execution by remote attackers.
2
How do I fix CVE-2024-28394?
To fix CVE-2024-28394, update the Advanced Plugins reportsstatistics to version 1.3.21 or later.
3
What systems are affected by CVE-2024-28394?
CVE-2024-28394 affects versions of Advanced Plugins reportsstatistics prior to 1.3.21.
4
What potential impacts does CVE-2024-28394 have?
The vulnerability could allow a remote attacker to execute arbitrary code, compromising the security of the affected system.
5
Is there a workaround for CVE-2024-28394?
Until a patch is applied, disabling the Sales Reports, Statistics, Custom Fields & Export module can mitigate the risk posed by CVE-2024-28394.