CVE-2024-3799

Insecure handling of POST header parameter bodyincluded in requests being sent to an instance of the open-source projectPhoniebox allows an attacker to create a website, which  when visited by a user  will sendmalicious requests to multiple hosts on the local network. If such a request reaches the server, it will cause ashell command execution.


This issue affects Phoniebox in all releases through 2.7. Newer 2.x releases were not tested, but they might also be vulnerable. 
Phoniebox in version 3.0 and higher are not affected.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
CERT-PLCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---