← Back to browse · API

CVE-2024-35374

Severity
CRITICAL
CVSS
9.8
EPSS
0.02744
Risk score
40.16
CISA KEV
No
PoC
No
Published
2024-05-24
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-1660, GHSA-J6CV-98JX-MRWR, PYSEC-2026-426
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-1660

Description

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

References