systeminformation SSID Command Injection Vulnerability
Critical severity
GitHub Reviewed
Published
Sep 21, 2023
in
sebhildebrandt/systeminformation
•
Updated Nov 4, 2023
Description
Published to the GitHub Advisory Database
Sep 21, 2023
Reviewed
Sep 21, 2023
Published by the National Vulnerability Database
Sep 21, 2023
Last updated
Nov 4, 2023
Impact
SSID Command Injection Vulnerability
Patches
Problem was fixed with a parameter check. Please upgrade to version >= 5.21.7, Version 4 was not affected
Workarounds
If you cannot upgrade, be sure to check or sanitize parameter strings that are passed to wifiConnections(), wifiNetworks() (string only)
References
See also https://systeminformation.io/security.html
References