Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/175672/MagnusBilling-Remote-Command-Execution.html | |
https://eldstal.se/advisories/230327-magnusbilling.html | Exploit Mitigation Third Party Advisory |
https://github.com/magnussolution/magnusbilling7/commit/ccff9f6370f530cc41ef7de2e31d7590a0fdb8c3 | Patch |
Configurations
History
No history.
Information
Published : 2023-06-23 12:15
Updated : 2023-11-14 03:15
NVD link : CVE-2023-30258
Mitre link : CVE-2023-30258
CVE.ORG link : CVE-2023-30258
JSON object : View
Products Affected
magnussolution
- magnusbilling
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')