Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-26c6-c3h3-4qf7

Опубликовано: 27 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

EPSS

Процентиль: 63%
0.00449
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-94

Связанные уязвимости

nvd
12 месяцев назад

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

EPSS

Процентиль: 63%
0.00449
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-94