Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3h67-687r-7fpc

Опубликовано: 05 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling.

Versions 7.4 and below are known to be vulnerable.

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling.

Versions 7.4 and below are known to be vulnerable.

EPSS

Процентиль: 97%
0.37501
Средний

9.3 Critical

CVSS4

Дефекты

CWE-20

Связанные уязвимости

nvd
5 месяцев назад

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.

CVSS3: 8.6
fstec
9 месяцев назад

Уязвимость программного обеспечения для унифицированных коммуникаций и телемаркетинга ICTBroadcast, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.37501
Средний

9.3 Critical

CVSS4

Дефекты

CWE-20