CVE-2024-28048: Fortunefield Ffbull
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was unreachable, therefore, users should consider stop using ffBull ver.4.11.
Affected products
- Fortunefield Ffbull: version 4.11 only
Published 2024-03-26. Last modified 2026-06-17.