Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-66429
HistoryAug 12, 2023 - 12:00 a.m.

ScienceLogic SL1 Command Execution Vulnerability (CNVD-2023-66429)

2023-08-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
4
sciencelogic
inc
command execution
vulnerability
cnvd-2023-66429
ticket report generation
arbitrary commands

EPSS

0.001

Percentile

31.7%

ScienceLogic SL1 is an application from ScienceLogic, Inc. Connect your real estate together to automate multidirectional data flow and workflow. A command execution vulnerability exists in ScienceLogic SL1 11.1.2 and earlier versions, which stems from a failure of the Ticket Report Generation feature to properly filter construct command special characters, commands, etc., and can be exploited by an attacker to execute arbitrary commands on the system.

EPSS

0.001

Percentile

31.7%

Related for CNVD-2023-66429