CVE-2018-12312

Publication date

2018-12-04 17:00:00

Family

mitre

State

PUBLISHED

Description

OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter.