Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kiteworks Core has an OS Command Injection
Vulnerability Description
Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access. Version 9.2.0 contains a patch.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Kiteworks 操作系统命令注入漏洞
Vulnerability Description
Kiteworks是美国Kiteworks公司的一个安全私有网络数据软件。 Kiteworks 9.2.0之前版本存在操作系统命令注入漏洞,该漏洞源于命令执行功能允许经过身份验证的用户将命令输出重定向到任意文件位置,可能导致覆盖关键系统文件和权限提升。
CVSS Information
N/A
Vulnerability Type
N/A