Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35256
HistoryApr 26, 2022 - 11:39 a.m.

Command Injection

2022-04-2611:39:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.001 Low

EPSS

Percentile

48.9%

czproject/git-php is vulnerable to command injection. A remote attacker is able to use additional flags to perform command injections via the isRemoteUrlReadable function since the url and refs parameter passing process to the git ls-remote subcommand, allows additional flags to be set.

0.001 Low

EPSS

Percentile

48.9%

Related for VERACODE:35256