CVE-2024-57685

An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:sparkshop:sparkshop:*:*:*:*:*:*:*:*

History

25 Mar 2025, 16:34

Type Values Removed Values Added
CPE cpe:2.3:a:sparkshop:sparkshop:*:*:*:*:*:*:*:*
First Time Sparkshop
Sparkshop sparkshop
References () https://github.com/lhRaMk7/notebook/blob/main/phar_rce - () https://github.com/lhRaMk7/notebook/blob/main/phar_rce - Broken Link

25 Feb 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
Summary
  • (es) Un problema en Sparkshop v.1.1.7 y anteriores permite a un atacante remoto ejecutar código arbitrario a través de un archivo phar manipulado específicamente.
CWE CWE-77

24 Feb 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-24 23:15

Updated : 2025-03-25 16:34


NVD link : CVE-2024-57685

Mitre link : CVE-2024-57685

CVE.ORG link : CVE-2024-57685


JSON object : View

Products Affected

sparkshop

  • sparkshop
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')