PT-2019-9403 · Grouptime · Grouptime Teamwire Backend+1
Benjamin Braun
+4
·
Published
2019-06-28
·
Updated
2019-07-05
·
CVE-2018-17170
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grouptime Teamwire Desktop Client versions 1.5.1 through 1.9.0
Grouptime Teamwire backend versions prior to prod-2018-11-13-15-00-42
Description
The issue allows code injection via a template, leading to remote code execution.
Recommendations
For Grouptime Teamwire Desktop Client versions 1.5.1 through 1.9.0, update to version 1.9.0 or later.
For Grouptime Teamwire backend versions prior to prod-2018-11-13-15-00-42, update to a version after prod-2018-11-13-15-00-42.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grouptime Teamwire Desktop Client
Grouptime Teamwire Backend