PT-2025-3867 · Unknown · Exelban Stats
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
exelban stats versions up to 2.11.21
Description
A critical issue has been found in the
shouldAcceptNewConnection function of the XPC Service component, leading to command injection. This issue can be exploited locally.Recommendations
For versions up to 2.11.21, upgrade to version 2.11.22 to address this issue. As a temporary workaround, consider disabling the
shouldAcceptNewConnection function until a patch is available.Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Exelban Stats