Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NginxProxyManager 安全漏洞
Vulnerability Description
NginxProxyManager是NginxProxyManager个人开发者的用于管理 Nginx 代理主机的 Docker 容器,具有简单、强大的界面。 NginxProxyManager 2.11.3版本存在安全漏洞,该漏洞源于requestLetsEncryptSslWithDnsChallenge功能中存在命令注入问题,攻击者可通过添加 Let s Encrypt 证书实现远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A