CVE-2023-45158 Information
Oct 17, 2023
cve
Description
An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration) a crafted web request may execute an arbitrary OS command on the web server using the product.
Reference
http://web2py.com/init/default/download https://jvn.jp/en/jp/JVN80476432/ https://github.com/web2py/web2py/commit/936e2260b0c34c44e2f3674a893e96d2a7fad0a3 http://web2py.com/
Share on: