PT-2023-19044 · Geomatika · Geomatika Isigeo Web
Guilhem Rioux
+1
·
Publicado
2023-08-22
·
Atualizado
2023-08-25
·
CVE-2023-23564
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Geomatika IsiGeo Web version 6.0
Description
An issue was discovered that allows remote authenticated users to execute commands.
Recommendations
For Geomatika IsiGeo Web version 6.0, consider restricting access to sensitive areas of the application to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Geomatika Isigeo Web