PT-2021-9090 · Scytl · Scytl Svote
Anthony Schneiter
+1
·
Published
2021-02-27
·
Updated
2021-07-21
·
CVE-2019-25022
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Scytl sVote version 2.1
Description
An issue was discovered in Scytl sVote where an attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias. This is possible because the application calls
Runtime.getRuntime().exec() without validation, allowing for code injection.Recommendations
For Scytl sVote version 2.1, consider disabling the functionality that allows creating election-events and injecting payloads over event aliases until a patch is available. Restrict access to the
Runtime.getRuntime().exec() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scytl Svote