CVE-2024-35374

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:mocodo:mocodo_online:*:*:*:*:*:*:*:*

History

10 Jun 2025, 17:24

Type Values Removed Values Added
First Time Mocodo
Mocodo mocodo Online
CPE cpe:2.3:a:mocodo:mocodo_online:*:*:*:*:*:*:*:*
References () https://chocapikk.com/posts/2024/mocodo-vulnerabilities/ - () https://chocapikk.com/posts/2024/mocodo-vulnerabilities/ - Exploit, Third Party Advisory
References () https://github.com/laowantong/mocodo/blob/11ca879060a68e06844058cd969c6379214cc2a8/web/generate.php#L104-L158 - () https://github.com/laowantong/mocodo/blob/11ca879060a68e06844058cd969c6379214cc2a8/web/generate.php#L104-L158 - Product

28 May 2024, 17:15

Type Values Removed Values Added
Summary Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary SQL commands and potentially command injection, leading to remote code execution (RCE) under certain conditions. Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

24 May 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-24 21:15

Updated : 2025-06-10 17:24


NVD link : CVE-2024-35374

Mitre link : CVE-2024-35374


JSON object : View

Products Affected

mocodo

  • mocodo_online
CWE

No CWE.