CVE-2020-13124 (NVD)

2020-08-11

SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on the underlying operating system.

Products Sabnzbd
Type Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
First patch - None (likely due to unavailable code)
Links https://github.com/sabnzbd/sabnzbd/commits/develop
https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-9x87-96gg-33w2
https://sabnzbd.org/downloads