Security Advisory
CVE-2024-46257
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Lets Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.