O-CMS 1.0.0 Authenticated OS C... Note

O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script

Posted by Ron E on Sep 03Description O-CMS version 1.0.0 contains an authenticated OS command injection vulnerability in the AI CLI configuration functionality. An authenticated attacker with sufficient privileges can supply shell metacharacters and additional commands through the ai_cli_script parameter of /admin/settings/save. When the configured AI provider is subsequently tested through /admin/settings/test-ai, the attacker-controlled CLI value is executed in a...