Lucene search

K
osvGoogleOSV:GHSA-JCCV-3H4X-35MV
HistoryMay 13, 2022 - 1:42 a.m.

Codiad Vulnerable to Shell Command Injection

2022-05-1301:42:17
Google
osv.dev
3

7.1 High

AI Score

Confidence

Low

0.041 Low

EPSS

Percentile

92.2%

components/filemanager/class.filemanager.php in Codiad before 2.8.3 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type.

CPENameOperatorVersion
codiad/codiadeq1.3.6

7.1 High

AI Score

Confidence

Low

0.041 Low

EPSS

Percentile

92.2%