WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
References
Link | Resource |
---|---|
https://packetstormsecurity.com/files/167721/Sashimi-Evil-OctoBot-Tentacle.html | Third Party Advisory VDB Entry |
https://github.com/Nwqda/Sashimi-Evil-OctoBot-Tentacle | Exploit Third Party Advisory |
https://github.com/Drakkar-Software/OctoBot/blob/master/CHANGELOG.md | Third Party Advisory |
https://github.com/Drakkar-Software/OctoBot/issues/1966 | Exploit Third Party Advisory |
https://www.octobot.online/ | Vendor Advisory |
http://packetstormsecurity.com/files/167780/OctoBot-WebInterface-0.4.3-Remote-Code-Execution.html | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-07-16 17:15
Updated : 2022-07-22 14:30
NVD link : CVE-2021-36711
Mitre link : CVE-2021-36711
JSON object : View
Products Affected
octobot
- octobot
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type