Description
An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 18 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-09-18T14:02:11.090Z
Reserved: 2023-10-04T23:39:17.361Z
Link: CVE-2023-45158
Updated: 2024-08-02T20:14:19.011Z
Status : Modified
Published: 2023-10-16T08:15:09.990
Modified: 2024-11-21T08:26:27.417
Link: CVE-2023-45158
No data.
OpenCVE Enrichment
No data.
Weaknesses