NVD disclosure day

Published threat advisories for July 30, 2024

CVE advisoryCRITICAL

CVE-2024-39011

Prototype Pollution in chargeover redoc allows arbitrary code execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A prototype pollution vulnerability in chargeover redoc's `mergeObjects` function allows for arbitrary code execution or denial of service. This affects systems using the affected software, potentially leading to broader impacts. Confirming its use and exposure is crucial to assessing risk.

CVE advisoryCRITICAL

CVE-2024-6699

Mikafon MA7 SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Mikafon MA7 devices are affected by a SQL injection vulnerability that allows attackers to inject malicious SQL commands. This could lead to unauthorized access or manipulation of data. The vulnerability is network-accessible, meaning an attacker can reach it without authentication.