Security Advisory

CVE-2023-0164

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-01-18 00:00:00
Last updated 2025-04-03 19:29:49
Assigner Fluid Attacks
CVSS score not scored
State PUBLISHED

Description

OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-controlled parameter into a system function.