PT-2018-5680 · Fonality · Trixbox
Published
2018-02-16
·
Updated
2022-02-19
·
CVE-2017-14535
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
trixbox version 2.8.0.4
Description:
The issue is related to OS command injection via shell metacharacters in the
lang parameter to the "/maint/modules/home/index.php" API endpoint. This allows for potential exploitation.Recommendations:
For trixbox version 2.8.0.4, as a temporary workaround, consider restricting access to the "/maint/modules/home/index.php" API endpoint or sanitizing the
lang parameter to prevent shell metacharacter injection until a patch is available.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trixbox