An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jpcert

Published: 2023-10-16T07:53:52.134Z

Updated: 2023-10-16T07:53:52.134Z

Reserved: 2023-10-04T23:39:17.361Z


Link: CVE-2023-45158

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-16T08:15:09.990

Modified: 2023-10-18T19:58:13.557


Link: CVE-2023-45158

JSON object: View

cve-icon Redhat Information

No data.

CWE