PT-2022-26458 · Nako3Edit · Nako3Edit

Satoki Tsuji

·

Published

2022-12-05

·

Updated

2025-04-24

·

CVE-2022-42496

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nako3edit versions 3.3.74 and earlier
Description The issue allows a remote attacker to obtain the appkey of the product and execute an arbitrary OS command on the product. This is due to an OS command injection vulnerability in the editor component of nadesiko3 (PC Version).
Recommendations For versions 3.3.74 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-42496
GHSA-7249-8X22-4RG4

Affected Products

Nako3Edit