Security Advisory

CVE-2023-45158

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-10-16 07:53:52
Last updated 2024-09-18 14:02:11
Assigner jpcert
CVSS score not scored
State PUBLISHED

Description

An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.