Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-639w-2r2j-2x43

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.

EPSS

Процентиль: 91%
0.06371
Низкий

7.2 High

CVSS3

Дефекты

CWE-306
CWE-78

Связанные уязвимости

CVSS3: 5.5
nvd
больше 4 лет назад

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.

EPSS

Процентиль: 91%
0.06371
Низкий

7.2 High

CVSS3

Дефекты

CWE-306
CWE-78