NA

CVE-2023-31465

Published: 26/07/2023 Updated: 03/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in FSMLabs TimeKeeper 8.0.17 up to and including 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server.

Vulnerable Product Search on Vulmon Subscribe to Product

fsmlabs timekeeper

Vendor Advisories

Check Point Reference: CPAI-2023-1435 Date Published: 8 Jan 2024 Severity: Critical ...