Impact
The vulnerability resides in the nmap_newscan function of functions_nmap.py in WebMap. By manipulating the target/params argument an attacker can inject arbitrary OS commands. This allows remote execution of commands on the server hosting WebMap, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
SabyasachiRana WebMap, any release up to commit 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25, all users of the New Nmap Scan Handler component.
Risk and Exploitability
The CVSS base score of 6.9 indicates a moderate severity threat. The EPSS score is 1%, indicating a low but nonzero probability of exploitation. The vulnerability is disclosed publicly and can be leveraged remotely. The attack can be executed over the network by providing crafted parameters to the Nmap scan endpoint without authentication, assuming no additional controls are in place. The vulnerability is not yet listed in CISA's KEV catalog.
OpenCVE Enrichment