Command Injection in sofianehamlaoui/lockdoor-framework
Valid
Reported on
Jun 27th 2021
✍️ Description
CI in Spaghetti function when it asks for custom agent.
🕵️♂️ Proof of Concept
// PoC
https://drive.google.com/file/d/11ljFoTHf_ge9tA2p9uezV9s_1PvM62VC/view?usp=sharing
💥 Impact
command run as root. So an attacker could do potential damage to the machine.
Occurrences
We have contacted a member of the
sofianehamlaoui/lockdoor-framework
team and are waiting to hear back
2 years ago
to join this conversation