Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Codexlynx

#22708of 53,611
10Total CVSS
Vulnerabilities · 1
PT-2021-9092
10
2021-02-19
Unknown · Openrepeater · CVE-2019-25024
**Name of the Vulnerable Software and Affected Versions** OpenRepeater versions prior to 2.2 **Description** The issue allows unauthenticated command injection via shell metacharacters in the `post service` parameter of the "functions/ajax system.php" API endpoint. **Recommendations** For versions prior to 2.2, update to version 2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "functions/ajax system.php" API endpoint to prevent unauthenticated command injection. Avoid using the `post service` parameter in the affected API endpoint until the issue is resolved.