Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fqc-3xm7-xmjv

Опубликовано: 30 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double quote characters.

tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double quote characters.

EPSS

Процентиль: 27%
0.00096
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double quote characters.

EPSS

Процентиль: 27%
0.00096
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-78