PT-2019-20064 · Wiki Plugin · Wiki-Plugin-Datalog

Publicado

2019-06-13

·

Atualizado

2019-06-13

CVSS v3.1

6.5

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions wiki-plugin-datalog versions prior to 0.1.6
Description The issue is related to Command Injection due to the package's failure to sanitize URLs on the curl endpoint. This allows attackers to inject commands, which could lead to Remote Code Execution on the system.
Recommendations Upgrade to version 0.1.6 or later.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-PM52-WWRW-C282

Produtos afetados

Wiki-Plugin-Datalog