← Back to browse · API

CVE-2024-30247

Severity
CRITICAL
CVSS
10.0
EPSS
0.02122
Risk score
40.74
CISA KEV
No
PoC
No
Published
2024-03-29
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-28178
Products
nextcloud:nextcloudpi, nextcloud:nextcloudpi < 1.53.1
Sources
euvd EUVD-2024-28178

Description

NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a security misconfiguration this can be used by anyone with access to NextCloudPi web-panel, no authentication is required. It is recommended that the NextCloudPi is upgraded to 1.53.1.

References