Lucene search

K
osvGoogleOSV:GHSA-MPX3-MX2P-9GV3
HistoryMay 17, 2022 - 4:46 a.m.

Improper Neutralization of Special Elements used in a Command in FitNesse Wiki

2022-05-1704:46:05
Google
osv.dev
8

0.064 Low

EPSS

Percentile

93.7%

FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page.