OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.
References
Link Resource
https://github.com/OpenRepeater/openrepeater/issues/66 Exploit Third Party Advisory
https://github.com/codexlynx/CVE-2019-25024 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-02-19T03:37:04

Updated: 2021-02-19T18:30:22

Reserved: 2021-02-19T00:00:00


Link: CVE-2019-25024

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-02-19T04:15:12.160

Modified: 2021-02-24T20:16:04.270


Link: CVE-2019-25024

JSON object: View

cve-icon Redhat Information

No data.

CWE