CVE-2022-46387

ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to change the title and then execute it as commands.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cmder:cmder:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:maximus5:conemu:*:*:*:*:*:*:*:*

History

19 Feb 2025, 19:15

Type Values Removed Values Added
References (MISC) https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md - Release Notes () https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md - Release Notes
References (MISC) https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e - Third Party Advisory () https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e - Third Party Advisory
CPE cpe:2.3:a:cmder_project:cmder:*:*:*:*:*:*:*:*
cpe:2.3:a:conemu_project:conemu:*:*:*:*:*:*:*:*
cpe:2.3:a:cmder:cmder:*:*:*:*:*:*:*:*
cpe:2.3:a:maximus5:conemu:*:*:*:*:*:*:*:*
First Time Cmder cmder
Maximus5 conemu
Cmder
Maximus5

05 Apr 2023, 03:37

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md - (MISC) https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md - Release Notes
References (MISC) https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e - (MISC) https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e - Third Party Advisory
CPE cpe:2.3:a:conemu_project:conemu:*:*:*:*:*:*:*:*
cpe:2.3:a:cmder_project:cmder:*:*:*:*:*:*:*:*
First Time Conemu Project conemu
Cmder Project cmder
Cmder Project
Conemu Project

Information

Published : 2023-03-28 20:15

Updated : 2025-02-19 19:15


NVD link : CVE-2022-46387

Mitre link : CVE-2022-46387


JSON object : View

Products Affected

cmder

  • cmder

maximus5

  • conemu