CVE-2023-45158
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 3.7%
probabilidade de exploração
3.7%top 11% das CVEs
exploração observada
nãonenhuma fonte reporta
An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.
Produtos afetados
web2py · web2py