Security Advisory

CVE-2022-36749

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-08-30 21:27:46
Last updated 2024-08-03 10:14:27
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.