2 results (0.004 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

27 Sep 2023 — An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList component. Un problema en PGYER codefever v.2023.8.14-2ce4006 permite a un atacante remoto ejecutar código arbitrario a través de una solicitud manipulada al componente BranchList. • https://gist.github.com/one-pyy/330548f740415dff49f59d56e14b4219 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 1

07 Apr 2023 — codefever before 2023.2.7-commit-b1c2e7f was discovered to contain a remote code execution (RCE) vulnerability via the component /controllers/api/user.php. • https://github.com/PGYER/codefever/issues/140 • CWE-94: Improper Control of Generation of Code ('Code Injection') •