Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface
Vulnerability Description
OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary C# code on the server host by creating or modifying job configurations. Attackers can leverage the plain C# execution mode, which lacks reference filtering or API restrictions, to access the file system, spawn processes, and invoke arbitrary .NET APIs as the process user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
OpenBullet2 代码注入漏洞
Vulnerability Description
OpenBullet2是openbullet个人开发者的一个跨平台自动化测试与数据抓取工具。 OpenBullet2 0.3.2及之前版本存在代码注入漏洞,该漏洞源于作业配置功能,可能导致经过身份验证的用户在服务器主机上执行任意C#代码,攻击者可利用纯C#执行模式访问文件系统、生成进程和调用.NET API。
CVSS Information
N/A
Vulnerability Type
N/A