CVE-2024-32651

Scores

EPSS

0.925high92.5%
0%20%40%60%80%100%

Percentile: 92.5%

CVSS

10.0critical3.x
0246810

CVSS Score: 10.0/10

All CVSS Scores

CVSS 3.x
10.0

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn’t required by the application (not by default and not enforced).

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

anchore_overrides

CWEs

CWE-1336

Exploits

Exploit ID: CVE-2024-32651

Source: github-poc

URL: https://github.com/s0ck3t-s3c/CVE-2024-32651-changedetection-RCE

Vulnerable Software (1)

Type: Configuration

Operating System:

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:changedetection:changedetection:*:*:*:*:*:python:*:*",          "versionEndIncluding": "0.45.20"        }    ...

Source: anchore_overrides

End of list