CVE-2024-23827: Nginxui Nginx UI
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue.
Affected products
- Nginxui Nginx UI: version 1.2.0 only; version 1.2.1 only; version 1.2.2 only; version 1.3.0 only; version 1.3.1 only; version 1.3.2 only; …
Published 2024-01-29. Last modified 2026-06-17.