CVE-2024-28187 is an OS Command Injection vulnerability affecting SOY CMS versions prior to 3.14.2, allowing authenticated administrators to execute arbitrary OS commands via specially crafted filenames during file uploads, specifically impacting the jpegoptim functionality. This high-severity vulnerability (CVSS 7.2) has a network attack vector and low attack complexity, enabling full compromise of confidentiality, integrity, and availability. While no known exploits or active exploitation have been observed, and community discussion is minimal, users are strongly advised to upgrade to version 3.14.2 as there are no workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.14.2CPE matchmatch criteria | cpe:2.3:a:saitodev:soy_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.