VDB
Sign up
CRITICAL9.8

GHSA-7c28-wg7r-pg6f

RaspAP Command Injection vulnerability

Quick fix

GHSA-7c28-wg7r-pg6f — billz/raspap-webgui: upgrade to the fixed version with the command below.

composer require billz/raspap-webgui:^2.8.8

Details

A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the `cfg_id` parameter in `/ajax/openvpn/activate_ovpncfg.php` and `/ajax/openvpn/del_ovpncfg.php`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/billz/raspap-webgui
Introduced in: 2.8.0Fixed in: 2.8.8
Fixcomposer require billz/raspap-webgui:^2.8.8

References