Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2868-gw76-97vq

Опубликовано: 14 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

EPSS

Процентиль: 42%
0.00194
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-119
CWE-78

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted vulnerable binary, including the ability to log in via the web server.

EPSS

Процентиль: 42%
0.00194
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-119
CWE-78