Mehrere Schwachstellen (CVE-2026-12257, CVE-2026-13014, CVE-2026-44963, CVE-2026-60121, CVE-2026-61498, CVE-2026-6847) in Vitec

Vitec - Flamingo - CRITICAL - CVE-2026-61498. Vitec Flamingo version 4.12.2 is susceptible to an OS command injection vulnerability through the admin/ajax/gen_graphs.php endpoint. This vulnerability allows remote attackers to execute arbitrary shell commands by manipulating the HTTP GET parameters, including start, end, key, or format. The lack of input sanitization in the graph generation script enables attackers to send crafted input that is directly passed to the shell commands without adequate validation, leveraging the web server context's passwordless sudo access. This poses a significant risk as it provides attackers with the potential to run commands with elevated privileges. BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io