Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Remote Code Inclusion. This issue affects Library Automation System: from v.19.5 before v.22.1.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
v.19.5 (custom) before v.22.1
Credits
anonymous
References
siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0240