Beveiligingsadvies

CVE-2022-25229

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-05-20 11:01:18
Laatst bijgewerkt 2024-08-03 04:36:06
Toegewezen door Fluid Attacks
CVSS-score geen score
Status PUBLISHED

Beschrijving

Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.