Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sameer Mohite

Researcher fromMandiant
#24660of 53,632
9.8Total CVSS
Vulnerabilities · 1
PT-2023-21848
9.8
2023-09-15
Unknown · Freewill Ifis · CVE-2023-28614
**Name of the Vulnerable Software and Affected Versions** Freewill iFIS (aka SMART Trade) version 20.01.01.04 **Description** The issue allows OS Command Injection via shell metacharacters to a report page. **Recommendations** For Freewill iFIS (aka SMART Trade) version 20.01.01.04, consider restricting access to the report page to minimize the risk of exploitation until a patch is available. Avoid using shell metacharacters in the report page. At the moment, there is no information about a newer version that contains a fix for this vulnerability.