A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
References
Link | Resource |
---|---|
http://mirth.com | Product |
http://nextgen.com | Product |
http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command-Execution.html | |
https://www.ihteam.net/advisory/mirth-connect | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-08-03 03:15
Updated : 2024-01-31 18:15
NVD link : CVE-2023-37679
Mitre link : CVE-2023-37679
CVE.ORG link : CVE-2023-37679
JSON object : View
Products Affected
nextgen
- mirth_connect
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')