CVE-2024-29185
CVSS 3.1 Score 9 of 10 (high)
Details
Summary
CVE-2024-29185 is a vulnerability affecting versions prior to 1.8.128 of the FreeScout help desk and shared mailbox software. The issue stems from the /public/tools.php source file in which the php_path parameter is executed as an OS command using the shell_exec function without proper validation. This OS Command Injection vulnerability allows an attacker, with knowledge of the `App_Key`, to execute malicious commands on the server, potentially leading to a complete compromise of the server, as demonstrated by the extraction of the /etc/passwd file. The complexity of this attack is high due to the requirement of obtaining the `App_Key`. The vulnerability has been patched in version 1.8.128.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.