Описание
A vulnerability, which was classified as critical, has been found in anji-plus AJ-Report up to 1.4.1. This issue affects the function IGroovyHandler. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266267.
Ссылки
- Exploit
- Broken Link
- Permissions RequiredVDB Entry
- Permissions RequiredVDB Entry
- Exploit
- Broken Link
- Permissions RequiredVDB Entry
- Permissions RequiredVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.1 (включая)
cpe:2.3:a:anji-plus:aj-report:*:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01047
Низкий
6.3 Medium
CVSS3
9.8 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-77
EPSS
Процентиль: 77%
0.01047
Низкий
6.3 Medium
CVSS3
9.8 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-77