Command Injection
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.4epss 2.6%
probabilidade de exploração
2.6%top 16% das CVEs
exploração observada
nãonenhuma fonte reporta
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Produtos afetados
Tenable, Inc. · Security CenterReferências
https://www.tenable.com/security/tns-2026-19