VDB
Sign up
HIGH8.8

GHSA-7r88-wjhj-jr8m

RaspAP Command Injection vulnerability

Quick fix

GHSA-7r88-wjhj-jr8m — billz/raspap-webgui: upgrade to the fixed version with the command below.

composer require billz/raspap-webgui:^2.9.5

Details

A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the `entity` POST parameters in `/ajax/networking/get_wgkey.php`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/billz/raspap-webgui
Introduced in: 2.8.0Fixed in: 2.9.5
Fixcomposer require billz/raspap-webgui:^2.9.5

References