CVE-2023-6899
Dashboard / Vulnerabilities / CVE-2023-6899
CVE-2023-6899
Summary: rmountjoy92 DashMachine Config save_config code injection
Details: A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of the file /settings/save_config of the component Config Handler. The manipulation of the argument value_template leads to code injection. The exploit has been disclosed to the public and may be used. The identifier VDB-248257 was assigned to this vulnerability.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/6xxx/CVE-2023-6899.json, https://nvd.nist.gov/vuln/detail/CVE-2023-6899, https://vuldb.com/?id.248257, https://vuldb.com/?ctiid.248257, https://treasure-blarney-085.notion.site/DashMachine-Unauthorized-RCE-931a35a81af9448ebe9fb4cd904d4a0c
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
