PT-2025-16875 · Unknown · Whoogle Search
Published
2025-04-16
·
Updated
2025-06-24
·
CVE-2024-53305
CVSS v4.0
8.9
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |
Name of the Vulnerable Software and Affected Versions
Whoogle search version 0.9.0
Description
The issue allows attackers to execute arbitrary code via supplying a crafted search query in the /models/config.py component.
Recommendations
For Whoogle search version 0.9.0, consider restricting access to the
config.py module to minimize the risk of exploitation until a patch is available.Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Whoogle Search