CVE ID | CVE-2024-9150 |
Publication date | 21 February 2025 |
Vendor | Wyn Enterprise |
Product | Wyn Enterprise |
Vulnerable versions | All before 8.0.00204.0 |
Vulnerability type (CWE) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Wyn Enterprise software and participated in coordination of its disclosure.
Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges account in order to abuse this functionality and execute malicious code, load DLL libraries and executing OS commands on a host system with applications high privileges.
This vulnerability was assigned CVE-2024-9150 and has been fixed in version 8.0.00204.0
Credits
We thank Maksym Brzęczek (efigo.pl) for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.