PT-2020-21555 · Unknown · Wizard-Syncronizer
Published
2020-09-11
·
Updated
2020-09-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
wizard-syncronizer versions (all)
Description
The issue concerns a command injection problem. It arises because the
cloneAndSync function does not validate input and concatenates it to an exec call. This can be exploited through a malicious widget with a payload in the gitURL value or via a Man-In-The-Middle (MITM) attack, as the package does not enforce HTTPS. This could allow attackers to execute arbitrary system commands.Recommendations
For all versions, consider using an alternative module until a fix is made available.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wizard-Syncronizer