2024-12-26

Intumit SmartRobot′s Conversational AI Platform - Improper Control of Generation of Code ('Code Injection')

ZUSOART ID ZA-2024-13
CVE ID CVE-2024-12652
Vulnerability Type CWE-94: Improper Control of Generation of Code ('Code Injection')
CVSS 4.0 Base CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H(9.3)
Description A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.
Vendor Intumit, Inc
Product
Category Version affected
SmartRobot′s Conversational AI Platform Before v7.2.0
Product Support Contact Intumit.
Release date 2024/12/26
Credit Cheng Ming Yang (TW1943) of ZUSO ART
top