GHSA-q5h6-49gg-2wfg
Dashboard / Vulnerabilities / GHSA-q5h6-49gg-2wfg
GHSA-q5h6-49gg-2wfg
Summary: GramAddict bot uses dependency with reverse tcp backdoor
Details: GramAddict before 1.2.5 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent. The attacker must be able to reach TCP port 7912, e.g., by being on the same Wi-Fi network.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-36245, https://github.com/GramAddict/bot/issues/134, https://github.com/GramAddict/bot/pull/183, https://github.com/GramAddict/bot/commit/b9d11691b2fb13749c3cd0f75c70ee31242053ce, https://github.com/GramAddict/bot, https://github.com/pypa/advisory-database/tree/main/vulns/gramaddict/PYSEC-2021-65.yaml
Affected packages
Package
Name: gramaddict
Purl: pkg:pypi/gramaddict
Affected ranges
Type: ECOSYSTEM
Events:
