CVE-2021-46704 GenieACS Command Injection POC# CVE-2021-46704-POC
CVE-2021-46704 GenieACS Command Injection POC
Affecting genieacs package, versions >=1.2.0 <1.2.8
# How to fix?
Upgrade genieacs to version 1.2.8 or higher.
Affected versions of this package are vulnerable to Command Injection via the ping host argument (lib/ui/api.ts and lib/ping.ts) which stems from insufficient input validation combined with a missing authorization check.
[4.0K] /data/pocs/16f8042a8d8bace2d0d88616e9480907cbe8aaf8
├── [1.7K] poc.py
└── [ 404] README.md
0 directories, 2 files