Description
NZBGet 21.1 allows authenticated remote code execution because the unarchive programs (7za and unrar) preserve executable file permissions. An attacker with the Control capability can execute a file by setting the value of SevenZipCommand or UnrarCmd. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://nzbget.net/download |
|
| https://sec.maride.cc/posts/nzbget/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T21:46:29.049Z
Reserved: 2023-11-21T00:00:00.000Z
Link: CVE-2023-49102
No data.
Status : Modified
Published: 2023-11-22T22:15:08.867
Modified: 2024-11-21T08:32:49.773
Link: CVE-2023-49102
No data.
OpenCVE Enrichment
No data.
Weaknesses