PT-2023-31114 · Unknown · Ironman Powershell Universal

Héctor Cavalcanti Saavedra

·

Publicado

2023-11-23

·

Atualizado

2023-11-30

·

CVE-2023-49213

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ironman PowerShell Universal versions 3.0.0 through 4.2.0
Description The issue allows remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. This is related to API endpoints.
Recommendations For versions 3.0.0 through 3.10.1, update to version 3.10.2. For versions 4.1.0 through 4.1.9, update to version 4.1.10. For versions 4.2.0, update to version 4.2.1.

Exploit

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-49213

Produtos afetados

Ironman Powershell Universal