CVE-2024-7565 is a directory traversal vulnerability in SMARTBEAR SoapUI's unpackageAll function, allowing remote attackers to achieve arbitrary code execution. This high-severity flaw (CVSS 7.8) requires user interaction, such as opening a malicious file, to exploit, leading to code execution in the context of the current user. While no public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation are currently reported, and community discussion is minimal, the potential for complete compromise of confidentiality, integrity, and availability is significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
.5.7.0CPE matchmatch criteria | cpe:2.3:a:smartbear:soapui:.5.7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.