{"id":"CVE-2024-35374","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-35374","summary":"Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially…","details":"Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.","published":"2024-05-24T21:15:59.793","modified":"2026-06-17T07:34:50.340","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"https://chocapikk.com/posts/2024/mocodo-vulnerabilities/"},{"type":"WEB","url":"https://github.com/laowantong/mocodo/blob/11ca879060a68e06844058cd969c6379214cc2a8/web/generate.php#L104-L158"},{"type":"EXPLOIT","url":"https://chocapikk.com/posts/2024/mocodo-vulnerabilities/"},{"type":"WEB","url":"https://github.com/laowantong/mocodo/blob/11ca879060a68e06844058cd969c6379214cc2a8/web/generate.php#L104-L158"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T07:34:50.340"}}