Back to Database
Status published
Unknown
CVE-2024-28125
FitNesse all releases allows a remote authenticated attacker to execute...
Vulnerability Description
FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a vulnerability but a product specification and this is currently under further investigation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28125
Credits & Attribution
No credits recorded in the NVD database.
References
More from unclebob
View All →CVE-2024-42499
Improper limitation of a pathname to a restricted directory ('Path...
Medium
5.3
CVE-2024-39610
Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026....
Medium
6.1
CVE-2024-28128
Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319,...
Unknown
0
CVE-2024-28039
Improper restriction of XML external entity references vulnerability exists in...
Unknown
0
CVE-2024-23604
Cross-site scripting vulnerability exists in FitNesse all releases, which may...
Unknown
0
Affected Vendor
unclebob
View all reports →Affected Software
FitNesse
Vulnerable Versions:
all releases
Timeline
Official Publish:
March 18th, 2024
Last Modified:
September 19th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available