Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8r8-mhhg-vjch

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exec() without validation.

An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exec() without validation.

EPSS

Процентиль: 61%
0.00418
Низкий

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exec() without validation.

EPSS

Процентиль: 61%
0.00418
Низкий

Дефекты

CWE-94