PT-2022-21998 · Pypi · Texercise

Di1L0O

·

Published

2022-06-24

·

Updated

2022-07-06

·

CVE-2022-34066

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Texercise package in PyPI versions 0.0.1 through 0.0.12
Description The issue concerns a code execution backdoor in the Texercise package. This backdoor allows attackers to access sensitive user information, digital currency keys, and escalate privileges.
Recommendations For versions 0.0.1 through 0.0.12, consider removing or avoiding the use of the Texercise package until a secure version is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-34066

Affected Products

Texercise