9.8
CVSSv3

CVE-2024-22506

Vulnerability Summary

This vulnerability allows remote malicious users to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product implements a registration mechanism that can be used to create a user with a sufficient privilege level. The specific flaw exists within the loadFieldMatch method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of LOCAL SERVICE.

Vendor Advisories

Check Point Reference: CPAI-2024-0097 Date Published: 12 Mar 2024 Severity: Medium ...