ZDI-24-102: Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of Struts. The issue results from improper access control. An attacker can leverage this vulnerability to execute code in the context of LOCAL SERVICE.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-22512.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-102?
The severity of ZDI-24-102 is critical due to its potential for remote code execution without authentication.
How do I fix ZDI-24-102?
To fix ZDI-24-102, ensure to update Allegra to the latest patched version that addresses this vulnerability.
Who is affected by ZDI-24-102?
ZDI-24-102 affects installations of Allegra that have improper access control configurations.
Is authentication required to exploit ZDI-24-102?
No, authentication is not required to exploit ZDI-24-102, making it particularly dangerous.
What type of vulnerability is ZDI-24-102?
ZDI-24-102 is an improper access control vulnerability that allows for remote code execution.