Angular Expressions Vulnerability Let Attackers Gain Full System Access
ID: e45b45b6-1fda-59ab-8531-c43bbb29f4c9
STIX ID: report--e45b45b6-1fda-59ab-8531-c43bbb29f4c9
Feed Name: cybersecurityNews.com
Threat Score
A critical remote code execution vulnerability (CVE-2024-54152, CVSS 9.3) was discovered in the Angular Expressions module allowing attackers to break the sandbox via the "proto" property and execute arbitrary commands; a public PoC demonstrates the impact and the maintainer released version 1.4.3 to address the issue while recommending mitigations and audits for possible historic compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
