PT-2020-21555 · Unknown · Wizard-Syncronizer

Published

2020-09-11

·

Updated

2020-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions wizard-syncronizer versions (all)
Description The issue concerns a command injection problem. It arises because the cloneAndSync function does not validate input and concatenates it to an exec call. This can be exploited through a malicious widget with a payload in the gitURL value or via a Man-In-The-Middle (MITM) attack, as the package does not enforce HTTPS. This could allow attackers to execute arbitrary system commands.
Recommendations For all versions, consider using an alternative module until a fix is made available.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-WGW3-GF4P-62XC

Affected Products

Wizard-Syncronizer