PT-2023-26064 · Xalpha · Xalpha
Leeyangee
·
Published
2023-07-11
·
Updated
2023-07-18
·
CVE-2023-37659
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xalpha version 0.11.4
Description
The issue concerns Remote Command Execution (RCE) due to improper validation of user input, which is not checked to ensure it contains numerical values before being evaluated.
Recommendations
For xalpha version 0.11.4, ensure that user input is properly validated to prevent RCE attacks, specifically by checking that input values are numerical before evaluation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xalpha