CVE-2024-46506
13.05.2025, 16:15
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.Enginsight
Vendor | Product | Version |
---|---|---|
netalertx | netalertx | 23.01.14 ≤ 𝑥 < 24.10.12 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration