Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c26-wm2f-5pm9

Опубликовано: 06 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 9.8

Описание

A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands.

We have already fixed the vulnerability in the following version: License Center 1.9.43 and later

A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands.

We have already fixed the vulnerability in the following version: License Center 1.9.43 and later

EPSS

Процентиль: 82%
0.01659
Низкий

7.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: License Center 1.9.43 and later

CVSS3: 9.8
fstec
больше 1 года назад

Уязвимость программного средства управления лицензиями QNAP License Center, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 82%
0.01659
Низкий

7.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-78