ZeroHour

CVE-2022-23915

CVSS 3.1
8.8 high
EPSS
4%p89
Published
()
Modified
Description

The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.

Vendors
weblate
Products
weblate
Weakness
CWE-88
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.