PT-2023-7673 · Web2Py · Web2Py
Masashi Yamane
·
Published
2023-10-16
·
Updated
2023-11-05
·
CVE-2023-45158
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
web2py versions 2.24.1 and earlier
Description
A command injection vulnerability exists in the product. When configured to use notifySendHandler for logging, a crafted web request may execute an arbitrary OS command on the web server. This issue arises due to the lack of neutralization of special elements.
Recommendations
For versions 2.24.1 and earlier, consider disabling the notifySendHandler for logging until a patch is available to prevent potential exploitation. Restrict access to the web server to minimize the risk of arbitrary OS command execution. Avoid using the product with the vulnerable configuration to reduce the risk of command injection attacks.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Web2Py