PT-2022-26175 · Unknown · Super-Xray

4Ra1N

·

Published

2022-11-21

·

Updated

2023-06-27

·

CVE-2022-41945

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions super-xray version 0.1-beta
Description The issue is related to a vulnerability scanner GUI launcher. In the affected version, the URL is not filtered and is directly spliced into the command, resulting in a possible Remote Code Execution (RCE) issue.
Recommendations For super-xray version 0.1-beta, upgrade to super-xray 0.2-beta to resolve the issue. As a temporary workaround, consider filtering or validating URLs before they are spliced into commands to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-41945
GHSA-732J-763P-CVQG

Affected Products

Super-Xray