Rhino Security Labs

Technical Blog

CVE-2024-2448:
Authenticated Command Injection
In Progress Kemp LoadMaster

David Yesland
April 16, 2024

This blog covers 2 vulnerabilities discovered in LoadMaster load balancers. CVE-2024-2448 is an authenticated command injection vulnerability and CVE-2024-2449 is a Cross-Site Request Forgery (CSRF) protection bypass vulnerability. The CSRF…

CVE-2024-1212:
Unauthenticated Command Injection
In Progress Kemp LoadMaster

CVE-2024-23724:
Ghost CMS Stored XSS Leading to Owner Takeover

Silverpeas App: Multiple CVEs leading to File Read on Server

Tyler Ramsbey

During research on the Silverpeas Core application, the Rhino research team identified 8 new CVEs over the course of 2 weeks. The most severe of these is CVE-2023-47324, a Stored Cross-Site Scripting (XSS) vulnerability affecting the…