CVE-2022-1509: Command Injection Vulnerability in hestiacp/hestiacp
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
Other sources
Sed Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-1509?
CVE-2022-1509 is a Sed Injection Vulnerability found in the GitHub repository hestiacp/hestiacp prior to version 1.5.12.
How does CVE-2022-1509 affect Hestiacp Control Panel?
CVE-2022-1509 allows an authenticated remote attacker with low privileges to execute arbitrary code under root context in the Hestiacp Control Panel before version 1.5.12.
What is the severity of CVE-2022-1509?
CVE-2022-1509 has a severity rating of critical with a CVSS score of 8.8.
How can I fix CVE-2022-1509 in Hestiacp Control Panel?
To fix CVE-2022-1509, update Hestiacp Control Panel to version 1.5.12 or later.
Where can I find more information about CVE-2022-1509?
More information about CVE-2022-1509 can be found in the GitHub commit and the Huntr.dev bounty link provided.