Filtered by vendor Sourcefabric Subscriptions
Filtered by product Rpi-jukebox-rfid Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-36749 1 Sourcefabric 1 Rpi-jukebox-rfid 2023-08-08 9.8 Critical
RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.