PT-2021-19958 · Unknown · Proxyee-Down

Alvaro Muñoz

+1

·

Published

2021-08-16

·

Updated

2021-08-24

·

CVE-2021-32826

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Proxyee-Down (affected versions not specified)
Description Proxyee-Down is open source proxy software. An attacker may be able to run arbitrary commands on the system running Proxyee-Down by providing an extension script, for example, through a Man-in-the-Middle (MiTM) attack or by hosting a malicious extension.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of extension scripts or disabling the ability to run arbitrary commands on the system until a patch is available. Avoid using potentially malicious extensions and be cautious when hosting or using extension scripts from untrusted sources.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32826

Affected Products

Proxyee-Down