An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows authenticated users to execute commands on the Operating System.
https://www.gruppotim.it/it/footer/red-team.html
Source: Mitre, NVD
Published: 2024-05-23
Updated: 2024-07-03
Base Score: 6.5
Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P
Severity: Medium
Base Score: 4.1
Vector: CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L