CVE-2019-16293: OS Command Injection
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16293?
CVE-2019-16293 is a vulnerability in the Create Discoveries feature of Open-AudIT before version 3.2.0 that allows an authenticated attacker to execute arbitrary OS commands.
How does CVE-2019-16293 impact Open-AudIT?
CVE-2019-16293 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field in the Create Discoveries feature of Open-AudIT.
What is the severity of CVE-2019-16293?
CVE-2019-16293 has a severity rating of 8.8 (High).
How can I fix CVE-2019-16293?
To fix CVE-2019-16293, upgrade Open-AudIT to version 3.2.0 or later.
Where can I find more information about CVE-2019-16293?
You can find more information about CVE-2019-16293 at the following link: [https://community.opmantek.com/display/OA/Errata+-+3.1.2+Security+issue%2C+September+2019](https://community.opmantek.com/display/OA/Errata+-+3.1.2+Security+issue%2C+September+2019)