Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jfx8-86f7-x4h2

Опубликовано: 26 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.

A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.

EPSS

Процентиль: 68%
0.00558
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-94

Связанные уязвимости

nvd
около 1 года назад

A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.

EPSS

Процентиль: 68%
0.00558
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-94