Back to all
2024-11-27

iota C.ai Conversational Platform - Improper Control of Generation of Code ('Code Injection')

ZUSOART ID
ZA-2024-12
CVE ID
CVE-2024-52959
Vulnerability Type
CWE-94: Improper Control of Generation of Code ('Code Injection')
CVSS 4.0 Base
9.3
Description

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

Vendor
Galaxy Software Services Corporation
Product
Category
Version affected
iota C.ai Conversational Platform
from 1.0.0 through 2.1.3
Mitigations

Update iota C.ai Conversational Platform to 2.2.0.Contact Galaxy Software Services Corporation for version updates.

Release date
2024-11-27
Credit

Jian You Chen (Jeremy Chen) of ZUSO ART