Mehrere Schwachstellen (CVE-2026-12257, CVE-2026-13014, CVE-2026-44963, CVE-2026-60121, CVE-2026-61498, CVE-2026-6847) in Vitec
⚠️ CVE-Referenzen:
CVE-2026-12257
CVE-2026-13014
CVE-2026-44963
CVE-2026-60121
CVE-2026-61498
CVE-2026-6847
Vitec - Flamingo - CRITICAL - CVE-2026-61498.
Vitec Flamingo version 4.12.2 is susceptible to an OS command injection vulnerability through the admin/ajax/gen_graphs.php endpoint. This vulnerability allows remote attackers to execute arbitrary shell commands by manipulating the HTTP GET parameters, including start, end, key, or format. The lack of input sanitization in the graph generation script enables attackers to send crafted input that is directly passed to the shell commands without adequate validation, leveraging the web server context's passwordless sudo access. This poses a significant risk as it provides attackers with the potential to run commands with elevated privileges.
BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io