peter bassill · operator
$ cve CVE-2024-27612 JSON

CVE-2024-27612 EXPLOIT

6.2
MEDIUM · CVSS 3.1 · EPSS 10.7% (pctl 96)

Patch early

A public exploit exists.

Description

Numbas editor before 7.3 mishandles editing of themes and extensions.

Scoring

CVSS6.2 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS10.71% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2024-03-08
Last modified2026-06-17

Affected (1)

VendorProduct
numbaseditor

Public exploits

SourceTitleDate
exploit-dbNumbas < v7.3 - Remote Code Execution2024-03-10

References

→ the Explorer  ·  watch your stack  ·  NVD