CVE-2024-39914: FOG has a command injection in /fog/management/export.php?filename=
Published Jul 12, 2024
·Updated
FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.
Affected Software
2 affected components
FOG FOG<1.5.10.34
fogproject fogproject<1.5.10.41
Remediation
Event History
Jul 12, 2024
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-39914?
CVE-2024-39914 is classified as a high severity vulnerability due to the command injection risk it poses.
2
How do I fix CVE-2024-39914?
To fix CVE-2024-39914, upgrade to FOG version 1.5.10.34 or later immediately.
3
What products are affected by CVE-2024-39914?
CVE-2024-39914 affects FOG versions prior to 1.5.10.34.
4
What type of vulnerability is CVE-2024-39914?
CVE-2024-39914 is a command injection vulnerability found in the FOG project.
5
Where is CVE-2024-39914 located in the software?
CVE-2024-39914 is located in the reportmaker.class.php file within the FOG management module.