CVE-2024-53412Disclosure

LOWCVSS 8.4 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-16)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-15: 1Mentions · 2026-04-16: 2Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 204-1504-16
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-151
General1
2026-04-162
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2024-53412 Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution v… https://www.cve.org/CVERecord?id=CVE-2024-53412 ----- Traducción: CVE-2024-53412 Iny… http://infoflow.cloud`

    Post summary

    The tweet announces a discovered command injection vulnerability in NietThijmen ShoppingCart 0.0.2 that enables arbitrary shell execution, but provides no PoC, exploit code, or evidence of active exploitation.

    0000043
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2024-53412 Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution v… https://www.cve.org/CVERecord?id=CVE-2024-53412

    Post summary

    A new command‑injection flaw in NietThijmen ShoppingCart 0.0.2 permits attackers to run arbitrary shell commands, leading to remote code execution.

    00000189
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2024-53412 Command Injection in NietThijmen ShoppingCart 0.0.2 Port Field Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-53412

    Post summary

    A brief notice identifies CVE-2024-53412 as a command injection in the Port Field of NietThijmen ShoppingCart 0.0.2 leading to RCE, but provides no PoC, exploit tool, patch information, or evidence of active exploitation.

    0000052
    4.0K followersView on X

Explore more