Unknown · Openrepeater · CVE-2019-25024
**Name of the Vulnerable Software and Affected Versions**
OpenRepeater versions prior to 2.2
**Description**
The issue allows unauthenticated command injection via shell metacharacters in the `post service` parameter of the "functions/ajax system.php" API endpoint.
**Recommendations**
For versions prior to 2.2, update to version 2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "functions/ajax system.php" API endpoint to prevent unauthenticated command injection. Avoid using the `post service` parameter in the affected API endpoint until the issue is resolved.