CVE-2024-46257

Publication date

2024-09-27 00:00:00

Family

mitre

State

PUBLISHED

Description

A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Lets Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.