← Back to browse · API

CVE-2024-21855

Severity
CRITICAL
CVSS
9.8
EPSS
0.02053
Risk score
39.92
CISA KEV
No
PoC
No
Published
2024-11-21
Modified
2024-11-21
First seen
2026-08-07
Aliases
EUVD-2024-19466, GHSA-C6QM-82C6-Q92V
Products
GoCast:GoCast 1.1.3
Sources
euvd EUVD-2024-19466

Description

A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

References