[0day-rubbish] Workflow Enterp... ノート

[0day-rubbish] Workflow Enterprise 9.1.0.1 Pre-authentication RCE (expression injection) (9.8)

投稿者: disclosure via Fulldisclosure 8月17日 宛先: fulldisclosure () seclists org 件名: [0day-rubbish] Workflow Enterprise 9.1.0.1 認証前RCE (式インジェクション) (9.8) 差出人: disclosure () 0day-rubbish com ----本文---- 0day Rubbish Research Team は、Workflow Enterprise 9.1.0.1 の脆弱性を公開します。タイプ: 認証前RCE (式インジェクション) (CWE-94) CVSS: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 影響: 認証なしでroot権限でのRCEが可能...