PT-2022-16118 · Unknown · Itunesrpc-Remastered
Benjjvi
·
Published
2022-02-01
·
Updated
2023-06-27
·
CVE-2022-23603
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
iTunesRPC-Remastered versions prior to commit 24f43aa
Description
The issue concerns a discord rich presence application for use with iTunes & Apple Music, where user input is not properly sanitized, allowing code injection. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
Recommendations
For versions prior to commit 24f43aa, upgrade to a version after commit 24f43aa as soon as possible to resolve the issue. As a temporary workaround, consider restricting user input to minimize the risk of code injection until a patch is available.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Itunesrpc-Remastered