Profelis It Consultancy · Sambabox · CVE-2022-25619
**Name of the Vulnerable Software and Affected Versions**
Profelis IT Consultancy SambaBox versions 4.0 and prior versions
**Description**
The issue is related to an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in the ping tool of Profelis IT Consultancy SambaBox. This allows an authenticated user to cause the execution of arbitrary code.
**Recommendations**
For versions 4.0 and prior, consider restricting access to the ping tool until a patch is available.
As a temporary workaround, consider disabling the ping tool function to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.