vendor:
op5 Monitor
by:
hyp3rlinx
8,8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: op5 Monitor
Affected Version From: 7.1.9
Affected Version To: 7.2.0
Patch Exists: YES
Related CWE: N/A
CPE: 2.3:a:op5:op5_monitor:7.1.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2020
OP5-REMOTE-CMD-EXECUTION
op5 has a CSRF entry point that can be used to execute arbitrary remote commands on op5 system sent via HTTP GET requests, allowing attackers to completely takeover the affected host, to be victimized a user must be authenticated and visit a malicious webpage or click an infected link.
Mitigation:
Upgrade to the latest version of op5 Monitor.