First published: Fri Sep 13 2019(Updated: )
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opmantek Open-AudIT | <3.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16293 is a vulnerability in the Create Discoveries feature of Open-AudIT before version 3.2.0 that allows an authenticated attacker to execute arbitrary OS commands.
CVE-2019-16293 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field in the Create Discoveries feature of Open-AudIT.
CVE-2019-16293 has a severity rating of 8.8 (High).
To fix CVE-2019-16293, upgrade Open-AudIT to version 3.2.0 or later.
You can find more information about CVE-2019-16293 at the following link: [https://community.opmantek.com/display/OA/Errata+-+3.1.2+Security+issue%2C+September+2019](https://community.opmantek.com/display/OA/Errata+-+3.1.2+Security+issue%2C+September+2019)