Filtered by vendor Fitnesse Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-28125 1 Fitnesse 1 Fitnesse 2024-10-10 9.8 Critical
FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a vulnerability but a product specification and this is currently under further investigation.
CVE-2014-1216 1 Fitnesse 1 Fitnesse Wiki 2024-08-06 N/A
FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page.