Home
HIGH: 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/S:N/AU:N/R:U/V:D/RE:M/U:GreenDefault status
unaffected
5.0.105 (custom) before 5.0.106
affected
Description
Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
5.0.105 (custom) before 5.0.106
Credits
h00die-gr3y (h00die.gr3y@gmail.com)
References
pandorafms.com/...rity/common-vulnerabilities-and-exposures/