Lucene search

K
githubGitHub Advisory DatabaseGHSA-7249-8X22-4RG4
HistoryDec 05, 2022 - 6:30 a.m.

nadesiko3 vulnerable to OS Command Injection

2022-12-0506:30:22
CWE-78
GitHub Advisory Database
github.com
8
vulnerable software
nako3edit
editor component
remote attacker
obtain appkey
arbitrary os command

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

77.8%

OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product.

Affected configurations

Vulners
Node
kujirahandnadesiko3Range<3.3.75
VendorProductVersionCPE
kujirahandnadesiko3*cpe:2.3:a:kujirahand:nadesiko3:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

77.8%

Related for GHSA-7249-8X22-4RG4