Описание
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
Ссылки
- Patch
- ExploitIssue TrackingPatchThird Party Advisory
- Patch
- ExploitIssue TrackingPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.12 (исключая)
cpe:2.3:a:hestiacp:control_panel:*:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.01681
Низкий
9.9 Critical
CVSS3
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-77
CWE-77
Связанные уязвимости
CVSS3: 8.8
github
почти 4 года назад
Sed Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
EPSS
Процентиль: 82%
0.01681
Низкий
9.9 Critical
CVSS3
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-77
CWE-77