← Back to browse · API

CVE-2024-7399

Severity
HIGH
CVSS
8.8
EPSS
0.91941
Risk score
57.18
CISA KEV
Yes
PoC
No
Published
2024-08-09
Modified
2026-04-25
First seen
2026-08-07
Aliases
EUVD-2024-48330, GHSA-9X68-238R-W7MQ
Products
Samsung Electronics:MagicINFO 9 Server 0 <21.1050, Samsung:MagicINFO 9 Server
Sources
cisa.gov CVE-2024-7399
euvd EUVD-2024-48330

Description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

References