Back

HIGH

jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection

Published Jan 20, 2023

Description

jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 20, 2023
Updated Apr 3, 2025
Reserved Jan 15, 2023
CISA Vulnrichment
Updated Apr 3, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a