CVE-2023-49213: Command Injection
Published Nov 23, 2023
·Updated
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.
Affected Software
3 affected components
Ironmansoftware Powershell Universal>=3.0.0<3.10.2
Ironmansoftware Powershell Universal>=4.1.0<4.1.10
Ironmansoftware Powershell Universal=4.2.0
Event History
Nov 23, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-49213.
2
What is the severity rating of CVE-2023-49213?
CVE-2023-49213 has a severity rating of 8.8 (High).
3
How can remote attackers exploit CVE-2023-49213?
Remote attackers can exploit CVE-2023-49213 by sending crafted HTTP requests to the API endpoints.
4
What software versions are affected by CVE-2023-49213?
The affected software versions are Ironman PowerShell Universal 3.0.0 through 4.2.0.
5
How can I fix CVE-2023-49213?
To fix CVE-2023-49213, update to the fixed versions of Ironman PowerShell Universal: 3.10.2, 4.1.10, or 4.2.1.