Fiche vulnérabilité
CVE-2023-0164 : faille élevée orangescrum orangescrum (CVSS 8.8)
Description
OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-controlled parameter into a system function.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 18 janv. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- orangescrum orangescrum