Skip to content

Remote code execution on ReconServer due to improper input sanitization on the prips command

Critical
DEMON1A published GHSA-fjcj-g7x8-4rp7 Jan 8, 2024

Package

ReconServer

Affected versions

0.0.8-beta

Patched versions

0.0.8

Description

Impact

Remote code execution, the attacker is able to execute shell commands in the server without having an admin role

Patches

The issue is fixed @ ReconServer 0.0.8, Please update to that version if you're anything below that

Workarounds

If you can't update just disable the prips command until you're able to update

References

#23
f9cb0f6

Severity

Critical

CVE ID

CVE-2024-21663

Weaknesses

Credits