The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2022-03-04T20:00:13.383792Z
Updated: 2024-09-17T00:10:54.741Z
Reserved: 2022-02-24T00:00:00
Link: CVE-2022-23915
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-03-04T20:15:07.757
Modified: 2024-11-21T06:49:27.273
Link: CVE-2022-23915
Redhat
No data.