📦 Fogproject

by Fogproject

🔍 What is Fogproject?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-58443

CRITICAL CVSS 9.1 Sep 6, 2025

This CVE describes an authentication bypass vulnerability in FOG Project versions 1.5.10.1673 and below that allows unauthenticated attackers to dump the entire SQL database. All organizations using v...

CVE-2024-39914

CRITICAL CVSS 9.8 Jul 12, 2024

This vulnerability allows remote attackers to execute arbitrary commands on FOG Project servers via command injection in the filename parameter. It affects all FOG Project installations prior to versi...

CVE-2024-40645

HIGH CVSS 8.8 Jul 31, 2024

This vulnerability allows authenticated users in FOG Project to upload malicious files disguised as images, leading to remote code execution on the server. Attackers can append PHP webshells to image ...

CVE-2024-34477

HIGH CVSS 7.8 May 27, 2024

CVE-2024-34477 is a local privilege escalation vulnerability in FOG Project's configureNFS function that allows authenticated local users to gain root privileges by mounting a malicious NFS share. The...

CVE-2023-46236

HIGH CVSS 8.6 Oct 31, 2023

CVE-2023-46236 is a server-side request forgery (SSRF) vulnerability in FOG Project that allows unauthenticated attackers to make arbitrary GET requests from the server to internal or external endpoin...

CVE-2021-32243

HIGH CVSS 8.8 Jun 16, 2021

CVE-2021-32243 is an authenticated file upload vulnerability in FOGProject that allows remote code execution. Attackers with valid credentials can upload malicious files to execute arbitrary commands ...

CVE-2024-42349

MEDIUM CVSS 5.3 Aug 2, 2024

FOG Server versions 1.5.10.41.4 and earlier store login logs in publicly accessible web server directories, exposing usernames, IP addresses, and user agents. This information disclosure vulnerability...

CVE-2024-41954

MEDIUM CVSS 5.3 Jul 31, 2024

CVE-2024-41954 is an information disclosure vulnerability in FOG Project where plaintext service account credentials are stored in a world-readable configuration file. Any local user on the host can r...