PT-2024-36004 · Unzip-Bot · Unzip-Bot

Edm115

·

Published

2024-12-02

·

Updated

2024-12-02

·

CVE-2024-53992

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: unzip-bot versions prior to 7.0.3a
Description: The issue allows users to exploit unsanitized inputs to inject malicious commands that are executed through subprocess.Popen with shell=True. Attackers can exploit this using a crafted archive name, password, or video name.
Recommendations: For versions prior to 7.0.3a, update to version 7.0.3a to resolve the issue. As a temporary workaround, consider restricting the use of subprocess.Popen with shell=True until the update is applied. Avoid using crafted archive names, passwords, or video names in the affected bot to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-53992
GHSA-34CG-7F8C-FM5H

Affected Products

Unzip-Bot