Note:
This project will be discontinued after December 13, 2021. [more]
2020-08-11
SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on the underlying operating system.
Products | Sabnzbd |
Type | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
First patch | - None (likely due to unavailable code) |
Links |
• https://github.com/sabnzbd/sabnzbd/commits/develop
• https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-9x87-96gg-33w2 • https://sabnzbd.org/downloads |