← Back to browse · API

CVE-2024-39914

Severity
CRITICAL
CVSS
9.8
EPSS
0.23237
Risk score
47.33
CISA KEV
No
PoC
No
Published
2024-07-12
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-38296
Products
FOGProject:fogproject < 1.5.10.34
Sources
euvd EUVD-2024-38296

Description

FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.

References