Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.
References
Link | Resource |
---|---|
http://super.com | Not Applicable |
https://www.mgm-sp.com/en/multiple-vulnerabilities-in-syncovery-for-linux/ | Exploit Third Party Advisory |
http://syncovery.com | Broken Link |
http://packetstormsecurity.com/files/170245/Syncovery-For-Linux-Web-GUI-Authenticated-Remote-Command-Execution.html | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-09-15 20:15
Updated : 2023-02-15 18:35
NVD link : CVE-2022-36534
Mitre link : CVE-2022-36534
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
syncovery
- syncovery
linux
- linux_kernel