Security advisory: Pre-authentication RCE in nanoDLP stable build #10729 (Nano3Dtech)
Posted by disclosure via Fulldisclosure on Aug 170day Rubbish Research Team is publicly disclosing a vulnerability in nanoDLP stable build #10729 (Nano3Dtech). The
research is published and a proof-of-concept is available. Pre-authentication RCE (CVSS 9.8, pre-authentication) nanoDLP exposes an unauthenticated remote code execution vulnerability. The Guest (unauthenticated) endpoint POST
/formula evaluates user-supplied JavaScript in an embedded Otto JS sandbox, which exposes a live nanoDLP...