PT-2022-11739 · Unknown · Feminer Wms
Leiyuyu041013
·
Published
2022-05-16
·
Updated
2022-07-12
·
CVE-2021-42897
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FeMiner wms version V1.0
Description
A remote command execution issue was found in FeMiner wms. The vulnerability is located in /wms/src/system/datarec.php, where the
r name variable from the $ POST request is directly passed into the $mysqlstr and executed by the exec() function. This allows for potential remote command execution.Recommendations
For FeMiner wms version V1.0, consider disabling the
exec() function in the /wms/src/system/datarec.php file until a patch is available. Additionally, restrict access to the datarec.php file to minimize the risk of exploitation. Avoid using the r name variable in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Feminer Wms