HIGH8.8
GHSA-7r88-wjhj-jr8m
RaspAP Command Injection vulnerability
Quick fix
GHSA-7r88-wjhj-jr8m — billz/raspap-webgui: upgrade to the fixed version with the command below.
composer require billz/raspap-webgui:^2.9.5Details
A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the `entity` POST parameters in `/ajax/networking/get_wgkey.php`.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/billz/raspap-webgui
Introduced in:
2.8.0Fixed in: 2.9.5Fix
composer require billz/raspap-webgui:^2.9.5References
- https://nvd.nist.gov/vuln/detail/CVE-2022-39987[ADVISORY]
- https://github.com/RaspAP/raspap-webgui/pull/1395[WEB]
- https://github.com/RaspAP/raspap-webgui/commit/e87e7d1d3a61617430851f2a040379de1ff3dd9d[WEB]
- https://github.com/RaspAP/raspap-webgui[PACKAGE]
- https://github.com/RaspAP/raspap-webgui/blob/master/ajax/networking/get_wgkey.php[WEB]
- https://github.com/RaspAP/raspap-webgui/releases/tag/2.9.5[WEB]
- https://medium.com/@ismael0x00/multiple-vulnerabilities-in-raspap-3c35e78809f2[WEB]