Skip to content

Remote Command Execution in file editing #6555

@unicorn-security-team

Description

@unicorn-security-team

Hello,

we are security researchers from Unicorn (https://unicorn.com/en/security) and we have identified a serious vulnerability that is exploitable from the position of a registered user. The vulnerability allows the Remote Command Execution, leading to full server takeover.

The details will be sent to [email protected] as requested.

Regards,

Marek Malcovský & Petr Pernikář

Metadata

Metadata

Assignees

Labels

💊 bugSomething isn't working🔒 securityCategorizes as related to security

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions