An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command.
References
Link | Resource |
---|---|
https://github.com/OpenGamePanel/OGP-Website/pull/561 | Third Party Advisory |
https://www.exploit-db.com/exploits/50373 | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2021-11-09 16:15
Updated : 2021-11-12 11:24
NVD link : CVE-2021-37158
Mitre link : CVE-2021-37158
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
opengamepanel
- opengamepanel