GHSA-38vf-35cg-m73w, CVE-2023-41564
packagist/cockpit-hq/cockpit
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.
All versions up to 2.6.3
Unfortunately, there is no solution available yet.
2023-09-12
source |