PT-2023-19044 · Geomatika · Geomatika Isigeo Web
Guilhem Rioux
+1
·
Published
2023-08-22
·
Updated
2023-08-25
·
CVE-2023-23564
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Geomatika IsiGeo Web version 6.0
Description
An issue was discovered that allows remote authenticated users to execute commands.
Recommendations
For Geomatika IsiGeo Web version 6.0, consider restricting access to sensitive areas of the application to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geomatika Isigeo Web