OS Command Injection in sofianehamlaoui/lockdoor-framework
Valid
Reported on
Jun 25th 2021
✍️ Description
Command Injection due to unsanitized variable named algo
🕵️♂️ Proof of Concept
💥 Impact
CI with the highest privilege.
Occurrences
We have contacted a member of the
sofianehamlaoui/lockdoor-framework
team and are waiting to hear back
2 years ago
2 years ago
2 years ago
Mohamed Dief
commented
2 years ago
Hey Sofiane, You're still vulnerable to arbitrary code execution. The fix has been applied doesn't protect from all cases, should i submit a new disclosure on huntr?
to join this conversation