Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.
CVE ID: CVE-2024-25600
CVSS Base Severity: CRITICAL
CVSS Base Score: 10.0
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vendor: Codeer Limited
Product: Bricks Builder
http/cves/2024/CVE-2024-25600.yaml
EPSS Score: 93.45% (probability of being exploited)
EPSS Percentile: 99.81% (scored less or equal to compared to others)
EPSS Date: 2025-07-03 (when was this score calculated)
SSVC Exploitation: poc
SSVC Technical Impact: total
SSVC Automatable: true