PT-2023-7673 · Web2Py · Web2Py

Masashi Yamane

·

Published

2023-10-16

·

Updated

2023-11-05

·

CVE-2023-45158

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions web2py versions 2.24.1 and earlier
Description A command injection vulnerability exists in the product. When configured to use notifySendHandler for logging, a crafted web request may execute an arbitrary OS command on the web server. This issue arises due to the lack of neutralization of special elements.
Recommendations For versions 2.24.1 and earlier, consider disabling the notifySendHandler for logging until a patch is available to prevent potential exploitation. Restrict access to the web server to minimize the risk of arbitrary OS command execution. Avoid using the product with the vulnerable configuration to reduce the risk of command injection attacks.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-08740
CVE-2023-45158

Affected Products

Web2Py