CVE-2024-50811: Tendcode Izone
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
hopetree izone lts c011b48 contains a server-side request forgery (SSRF) vulnerability in the active push function as \\apps\\tool\\apis\\bd_push.py does not securely filter user input through push_urls() and get_urls().
Affected products
- Tendcode Izone: any version
Published 2024-11-08. Last modified 2026-06-17.