Vulnerability CVE-2024-1297


Published: 2024-02-20

Description:
Loomio version 2.22.0 allows executing arbitrary commands on the server.

This is possible because the application is vulnerable to OS Command Injection.



Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

 References:
https://github.com/loomio/loomio
https://fluidattacks.com/advisories/stones

Copyright 2026, cxsecurity.com

 

Back to Top