CVE-2024-56086

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:*

History

17 Apr 2025, 01:50

Type Values Removed Values Added
CPE cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:*
References () https://servicedesk.logpoint.com/hc/en-us/articles/22136886421277-Remote-Code-Execution-while-creating-Report-Templates - () https://servicedesk.logpoint.com/hc/en-us/articles/22136886421277-Remote-Code-Execution-while-creating-Report-Templates - Vendor Advisory
First Time Logpoint siem
Logpoint

16 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-16 06:15

Updated : 2025-04-17 01:50


NVD link : CVE-2024-56086

Mitre link : CVE-2024-56086

CVE.ORG link : CVE-2024-56086


JSON object : View

Products Affected

logpoint

  • siem
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')