Description
OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-36792 | OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed. |
References
History
Fri, 03 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-01-03T19:23:14.601Z
Reserved: 2023-05-11T00:00:00.000Z
Link: CVE-2023-32548
Updated: 2024-08-02T15:18:37.622Z
Status : Modified
Published: 2023-06-13T10:15:10.573
Modified: 2025-01-03T20:15:26.993
Link: CVE-2023-32548
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD