CRITICAL
The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the create(), run_file(), backup(), or restore() function
Published Jun 8, 2018
9.8
CRITICALCVSS 3.0
EPSS 2.58%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.