CVE-2023-3267

CVE-2023-3267

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

Source: CVE-2023-3267

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다