CVE-2018-12483: OS Command Injection
OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscoveranalyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12483?
The severity of CVE-2018-12483 is categorized as medium, indicating a significant risk of exploitation.
How do I fix CVE-2018-12483?
To fix CVE-2018-12483, upgrade to OCS Inventory version 2.4.2 or later, where this vulnerability has been patched.
Who is affected by CVE-2018-12483?
CVE-2018-12483 affects users of OCS Inventory version 2.4.1, specifically those who have access to the affected PHP script.
What type of vulnerability is CVE-2018-12483?
CVE-2018-12483 is a remote command execution vulnerability that allows attackers to execute arbitrary commands on the server.
Is authentication required to exploit CVE-2018-12483?
Yes, authentication is required to exploit CVE-2018-12483, meaning that an attacker must have valid user credentials to execute the attack.