← Back to browse · API

CVE-2024-2448

Severity
HIGH
CVSS
8.4
EPSS
0.55422
Risk score
53.0
CISA KEV
No
PoC
No
Published
2024-03-22
Modified
2024-11-15
First seen
2026-08-07
Aliases
EUVD-2024-27397, GHSA-Q953-JQF9-XXC3
Products
Progress Software:LoadMaster, Progress Software:LoadMaster 7.1.35.10 <7.1.35.11 (LoadMaster MT), Progress Software:LoadMaster 7.2.48.10 <7.2.48.11 (LoadMaster LTS), Progress Software:LoadMaster 7.2.49.0 <7.2.54.9 ( LoadMaster LTSF), Progress Software:LoadMaster 7.2.55.0 <7.2.59.3 ( LoadMaster GA)
Sources
euvd EUVD-2024-27397

Description

An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.

References