Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3m3j-jxfh-jw6m

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.

EPSS

Процентиль: 70%
0.00638
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-78

Связанные уязвимости

nvd
около 2 месяцев назад

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.

EPSS

Процентиль: 70%
0.00638
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-78