Back to all
2024-12-26

Intumit SmartRobot′s Conversational AI Platform - Improper Control of Generation of Code ('Code Injection')

ZUSOART ID
ZA-2024-13
CVE ID
CVE-2024-12652
Vulnerability Type
CWE-94: Improper Control of Generation of Code ('Code Injection')
CVSS 4.0 Base
9.3
Description

A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.

Vendor
Intumit, Inc
Product
Category
Version affected
SmartRobot′s Conversational AI Platform
Before v7.2.0
Mitigations

Contact Intumit.

Release date
2024-12-26
Credit

Cheng Ming Yang (TW1943) of ZUSO ART