24 lines
1005 B
JSON
Raw Normal View History

{
"id": "CVE-2023-38316",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-11-17T06:15:33.617",
"lastModified": "2023-11-17T13:58:59.840",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en OpenNDS Captive Portal antes de la versi\u00f3n 10.1.2. Cuando la devoluci\u00f3n de llamada personalizada sin escape est\u00e1 habilitada, los atacantes pueden ejecutar comandos arbitrarios del sistema operativo insert\u00e1ndolos en la parte URL de las solicitudes HTTP GET."
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/openNDS/openNDS/releases/tag/v10.1.2",
"source": "cve@mitre.org"
}
]
}