Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-26c6-c3h3-4qf7

Опубликовано: 27 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

EPSS

Процентиль: 59%
0.00387
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-94

Связанные уязвимости

nvd
около 1 года назад

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

EPSS

Процентиль: 59%
0.00387
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-94