Security Research

CVE-2024-7954 Prote_plume Plugin RCE: from open-source security tool to unauthenticated RCE

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of security scanner tool and its own compromise irony

The Prote_plume security scanning plugin itself contains an unauthenticated RCE, CVSS 9.8. An attacker can execute arbitrary commands on the server with a simple request.

Unlock to view this content.