Impact
The vulnerability is an OS command injection that allows authenticated administrators to execute arbitrary shell commands as the web server process user. By configuring a malicious backup path and triggering a backup, the service concatenates the path into a tar shell command without sanitization, leading to persistent command execution on every backup operation. This flaw otherwise enables full compromise of the server running the web application.
Affected Systems
The affected product is sysPass from the vendor nuxsmin. All installations running version 3.2.11 or earlier are vulnerable. No other product versions are known to be impacted.
Risk and Exploitability
The CVSS score of 8.6 classifies the vulnerability as high severity, while an EPSS score of 2% indicates a very low but non-negligible exploitation probability at this time. Since it is not listed in CISA KEV, the likelihood of active attacks is presently low, but the impact is severe if exploitation occurs. An attacker must be an authenticated administrator, and based on the description, the attack vector is local to the application. Once the malicious backup path is set, subsequent backup triggers will execute the injected commands without further actions.
OpenCVE Enrichment