CVE-2018-16232
PoC —CVSS 3.1
8.8 high
EPSS
8%p94
Published
()
Modified
Description
An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated user with privileges for the affected page to execute arbitrary commands.
- Vendors
- ipfire
- Products
- ipfire
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.