OrangeScrum version 2.0.11 allows an... CVE-2023-0164

- AV AC AU C I A
发布: 2023-01-18
修订: 2023-01-28

OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-controlled parameter into a system function.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息