← Back to CVE List

CVE-2023-45158

Published: 2023-10-16T08:15Z
Last Modified: 2024-11-21T08:26Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt