A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.
CVE ID: CVE-2024-12652
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.3
Vendor: Intumit
Product: SmartRobot′s Conversational AI Platform
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.48% (scored less or equal to compared to others)
EPSS Date: 2025-02-04 (when was this score calculated)