VDB
Sign up
HIGH8.8

GHSA-4wwf-f7w3-94f5

RaspAP raspap-webgui contains an OS Command Injection vulnerability

Quick fix

GHSA-4wwf-f7w3-94f5 — billz/raspap-webgui: upgrade to the fixed version with the command below.

composer require billz/raspap-webgui:^3.3.6

Details

RaspAP raspap-webgui versions prior to 3.3.6 contain an OS Command Injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/billz/raspap-webgui
Introduced in: 0Fixed in: 3.3.6
Fixcomposer require billz/raspap-webgui:^3.3.6

References