PT-2022-16118 · Unknown · Itunesrpc-Remastered

Benjjvi

·

Published

2022-02-01

·

Updated

2023-06-27

·

CVE-2022-23603

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions iTunesRPC-Remastered versions prior to commit 24f43aa
Description The issue concerns a discord rich presence application for use with iTunes & Apple Music, where user input is not properly sanitized, allowing code injection. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
Recommendations For versions prior to commit 24f43aa, upgrade to a version after commit 24f43aa as soon as possible to resolve the issue. As a temporary workaround, consider restricting user input to minimize the risk of code injection until a patch is available.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2022-23603
GHSA-3XPP-RHQX-CW96

Affected Products

Itunesrpc-Remastered