CVE-2023-37198

CWE-94Code Injection3 documents3 sources
Severity
7.2HIGH
EPSS
2.2%
top 15.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12

Description

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
CVE-2023-37198: A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on2023-07-12
GHSA
GHSA-8x4r-qjgj-932v: A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on2023-07-12
CVE-2023-37198 (HIGH CVSS 7.2) | A CWE-94: Improper Control of Gener | cvebase.io