CVE-2024-23692Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

PUBLISHEDvulnerability record
2024-07-09 · last modified August 6, 2026

Metadata

CVE ID:
CVE-2024-23692
Project:
Rejetto
Product:
HTTP File Server
Date Added:
2024-07-09
Due Date:
2024-07-30
Last Updated:
August 6, 2026

Vulnerability Name

Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Description

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the affected system by sending a specially crafted HTTP request.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Additional Notes

Related News Articles

Related Weaknesses