vendor:
Payment Client
by:
Unknown
7.5
CVSS
HIGH
Arbitrary Command Execution
78
CWE
Product Name: Payment Client
Affected Version From: 1.6
Affected Version To: 1.7
Patch Exists: NO
Related CWE: None mentioned
CPE: a:ewire:payment_client:1.60 cpe:/a:ewire:payment_client:1.70
Platforms Tested: None mentioned
Unknown
Arbitrary Command Execution in ewire Payment Client
The ewire Payment Client is vulnerable to an arbitrary command execution vulnerability. Attackers can exploit this vulnerability by injecting malicious input, which is not properly sanitized by the software. This allows the attacker to execute arbitrary shell commands on the affected computer, with the privileges of the application using the affected class utility.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user-supplied input properly before using it in commands. Additionally, regular software updates and patches should be applied to ensure the latest security fixes are in place.