First published: Tue Nov 27 2018(Updated: )
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Terra-master Terramaster Operating System | =3.1.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13338 has a high severity rating due to its potential for remote command execution.
To fix CVE-2018-13338, upgrade your TerraMaster TOS to a version higher than 3.1.03.
The potential impacts of CVE-2018-13338 include unauthorized access to system commands and possible full system compromise.
CVE-2018-13338 affects TerraMaster Operating System version 3.1.03.
CVE-2018-13338 exploits the system by allowing attackers to inject system commands through the "username" parameter during user creation.