First published: Wed Apr 03 2024(Updated: )
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue affects VideoWhisper Live Streaming Integration: from n/a through 5.5.15.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress VideoWhisper Live Streaming Integration plugin | >=n/a<=5.5.15 | |
VideoWhisper Live Streaming Integration | <=5.5.15 |
Update to 5.5.16 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25699 has a critical severity level due to its potential for OS Command Injection.
To fix CVE-2023-25699, update VideoWhisper Live Streaming Integration to version 5.5.16 or later.
CVE-2023-25699 affects VideoWhisper Live Streaming Integration from n/a through version 5.5.15.
CVE-2023-25699 is classified as an OS Command Injection vulnerability.
Yes, there are reports indicating that CVE-2023-25699 can be exploited to execute arbitrary commands on the server.