A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. When this is combined with CVE-2019-14451, an attacker can upload an "external command" configuration as a printer configuration, and achieve remote code execution. After exploitation, loading of the external command configuration is dependent on a system reboot or service restart.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T00:19:40.999Z
Reserved: 2019-07-30T00:00:00
Link: CVE-2019-14450
No data.
Status : Modified
Published: 2019-10-28T17:15:19.877
Modified: 2024-11-21T04:26:45.937
Link: CVE-2019-14450
No data.
OpenCVE Enrichment
No data.
Weaknesses