SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService.list(), bareMetalService.list(), and switchService.list().
References
Link | Resource |
---|---|
https://github.com/fit2cloud/rackshift/issues/79 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-09-14 23:15
Updated : 2023-09-19 13:41
NVD link : CVE-2023-42405
Mitre link : CVE-2023-42405
CVE.ORG link : CVE-2023-42405
JSON object : View
Products Affected
fit2cloud
- rackshift
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')