NA

CVE-2024-23827

Published: 29/01/2024 Updated: 08/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9

Vulnerability Summary

Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue.

Vulnerable Product Search on Vulmon Subscribe to Product

nginxui nginx ui 2.0.0

nginxui nginx ui 1.2.0

nginxui nginx ui 1.2.1

nginxui nginx ui 1.2.2

nginxui nginx ui 1.3.0

nginxui nginx ui 1.3.1

nginxui nginx ui 1.3.2

nginxui nginx ui 1.3.3

nginxui nginx ui 1.4.0

nginxui nginx ui 1.4.1

nginxui nginx ui 1.4.2

nginxui nginx ui 1.5.0

nginxui nginx ui 1.5.1

nginxui nginx ui 1.5.2

nginxui nginx ui 1.6.0

nginxui nginx ui 1.6.1

nginxui nginx ui 1.6.2

nginxui nginx ui 1.6.3

nginxui nginx ui 1.6.5

nginxui nginx ui 1.6.6

nginxui nginx ui 1.6.7

nginxui nginx ui 1.6.8

nginxui nginx ui 1.7.0

nginxui nginx ui 1.7.1

nginxui nginx ui 1.7.2

nginxui nginx ui 1.7.3

nginxui nginx ui 1.7.4

nginxui nginx ui 1.7.5

nginxui nginx ui 1.7.6

nginxui nginx ui 1.7.7

nginxui nginx ui 1.7.8

nginxui nginx ui 1.7.9

nginxui nginx ui 1.8.0

nginxui nginx ui 1.8.1

nginxui nginx ui 1.8.2

nginxui nginx ui 1.8.3

nginxui nginx ui 1.8.4

nginxui nginx ui 1.9.9

nginxui nginx ui 1.9.9-1

nginxui nginx ui 1.9.9-2

nginxui nginx ui 1.9.9-3

nginxui nginx ui 1.9.9-4