Command Injection in wiki-plugin-datalog
High severity
GitHub Reviewed
Published
Jun 13, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 13, 2019
Published to the GitHub Advisory Database
Jun 13, 2019
Last updated
Jan 9, 2023
Versions of
wiki-plugin-datalog
prior to 0.1.6 are vulnerable to Command Injection. The package failed to sanitize URLs on the curl endpoint, allowing attackers to inject commands and possibly achieving Remote Code Execution on the system.Recommendation
Upgrade to version 0.1.6 or later.
References