CVE Published: 27/11/2024 |
CVE Updated: 27/11/2024 |
CVE Year: 2024 Source: ZUSO ART |
Vendor: Galaxy Software Services Corporation |
Product: iota C.ai Conversational Platform Status : PUBLISHED
CVE-2024-52959 Description
A Improper Control of Generation of Code (\'Code Injection\') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.