{ "id": "CVE-2024-26521", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-12T05:15:47.653", "lastModified": "2024-03-12T12:40:13.500", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component." }, { "lang": "es", "value": "Vulnerabilidad de inyecci\u00f3n HTML en CE Phoenix v1.0.8.20 y anteriores permite a un atacante remoto ejecutar c\u00f3digo arbitrario, escalar privilegios y obtener informaci\u00f3n confidencial a trav\u00e9s de un payload manipulado para el componente english.php." } ], "metrics": {}, "references": [ { "url": "https://github.com/capture0x/Phoenix", "source": "cve@mitre.org" }, { "url": "https://github.com/hackervegas001/CVE-2024-26521", "source": "cve@mitre.org" } ] }