CVE-2018-12307

Publication date

2018-12-04 17:00:00

Family

mitre

State

PUBLISHED

Description

OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.