HIGH8.8
GHSA-4wwf-f7w3-94f5
RaspAP raspap-webgui contains an OS Command Injection vulnerability
Quick fix
GHSA-4wwf-f7w3-94f5 — billz/raspap-webgui: upgrade to the fixed version with the command below.
composer require billz/raspap-webgui:^3.3.6Details
RaspAP raspap-webgui versions prior to 3.3.6 contain an OS Command Injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/billz/raspap-webgui
Introduced in:
0Fixed in: 3.3.6Fix
composer require billz/raspap-webgui:^3.3.6