PT-2018-12586 · Python · Conference-Scheduler-Cli

Joel

·

Published

2018-08-28

·

Updated

2020-08-24

·

CVE-2018-14572

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions conference-scheduler-cli (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary code via a crafted .pickle file. This is demonstrated by Python code that contains an os.system call, which can be used to execute system commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14572
GHSA-CF3C-FFFP-34QH
PYSEC-2018-64

Affected Products

Conference-Scheduler-Cli