PT-2019-20064 · Wiki Plugin · Wiki-Plugin-Datalog

Published

2019-06-13

·

Updated

2019-06-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions wiki-plugin-datalog versions prior to 0.1.6
Description The issue is related to Command Injection due to the package's failure to sanitize URLs on the curl endpoint. This allows attackers to inject commands, which could lead to Remote Code Execution on the system.
Recommendations Upgrade to version 0.1.6 or later.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-PM52-WWRW-C282

Affected Products

Wiki-Plugin-Datalog