CVE-2023-6899
rmountjoy92 DashMachine Config save_config code injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of the file /settings/save_config of the component Config Handler. The manipulation of the argument value_template leads to code injection. The exploit has been disclosed to the public and may be used. The identifier VDB-248257 was assigned to this vulnerability.
Una vulnerabilidad fue encontrada en rmountjoy92 DashMachine 0.5-4 y clasificada como problemática. Una función desconocida del archivo /settings/save_config del componente Config Handler es afectada por esta vulnerabilidad. La manipulación del argumento value_template conduce a la inyección de código. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-248257.
In rmountjoy92 DashMachine 0.5-4 wurde eine problematische Schwachstelle entdeckt. Betroffen ist eine unbekannte Verarbeitung der Datei /settings/save_config der Komponente Config Handler. Durch das Beeinflussen des Arguments value_template mit unbekannten Daten kann eine code injection-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-12-16 CVE Reserved
- 2023-12-17 CVE Published
- 2024-11-21 CVE Updated
- 2024-11-21 First Exploit
- 2025-01-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.248257 | Technical Description |
URL | Date | SRC |
---|---|---|
https://treasure-blarney-085.notion.site/DashMachine-Unauthorized-RCE-931a35a81af9448ebe9fb4cd904d4a0c | 2024-11-21 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rmountjoy92 Search vendor "Rmountjoy92" | Dashmachine Search vendor "Rmountjoy92" for product "Dashmachine" | 0.5-4 Search vendor "Rmountjoy92" for product "Dashmachine" and version "0.5-4" | - |
Affected
|