When adding a remote backup... CVE-2023-3267

- AV AC AU C I A
发布: 2023-08-14
修订: 2023-08-22

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息