CVE-2024-50492

Executive Summary

CVE-2024-50492 exposes an improper control of code generation flaw in ScottCart (versions up to 1.1), enabling attackers to inject and execute arbitrary code. The vulnerability can lead to remote code execution, data exfiltration, or full system compromise on affected installations. No current CISA KEV listing, but the flaw remains critical for any deployed ScottCart instance.


Authoritative CVE Metadata - CVSS Base Score: 8.3 (HIGH) - Published: 2024-10-28T12:15:16.973 - Last Modified: 2026-09-21T14:14:35.717

Original Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

"Through pride we are ever deceiving ourselves. But deep down below the surface of the average conscience a still, small voice says to us, Something is out of tune."

— Carl Jung
Source: NVD