### [CVE-2023-0164](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0164)



### Description
OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-controlled parameter into a system function.
### POC
#### Reference
- https://fluidattacks.com/advisories/queen/
#### Github
No PoCs found on GitHub currently.