Command Injection in sofianehamlaoui/lockdoor-framework
Valid
Reported on
Jun 27th 2021
✍️ Description
Unsanitized user input leads to command injection.
🕵️♂️ Proof of Concept
// PoC whatweb CI
https://drive.google.com/file/d/1mrYiu7oTaAm2qjLDKz23_VMUkiujafTh/view?usp=sharing
💥 Impact
command run as root. So an attacker could do potential damage to the machine.
Occurrences
We have contacted a member of the
sofianehamlaoui/lockdoor-framework
team and are waiting to hear back
2 years ago
to join this conversation