漏洞标题
Wyn Enterprise代码注入漏洞
漏洞描述信息
Wyn Enterprise中的报告生成功能允许代码包含,但未能充分限制可以包含的代码类型。攻击者可以使用低权限账户滥用此功能,执行恶意代码、加载DLL库并在主机系统上以较高权限执行操作系统命令。
此问题在版本8.0.00204.0中已得到修复。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
对搜索路径元素未加控制
漏洞标题
Code Injection in Wyn Enterprise
漏洞描述信息
Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges account in order to abuse this functionality and execute malicious code, load DLL libraries and executing OS commands on a host system with applications high privileges.
This issue has been fixed in version 8.0.00204.0
CVSS信息
N/A
漏洞类别
N/A