vendor:
7 Sticky Notes
by:
Ahmet Ümit BAYRAM
6.1
CVSS
HIGH
OS Command Injection
78
CWE
Product Name: 7 Sticky Notes
Affected Version From: 1.9.2024
Affected Version To: 1.9.2024
Patch Exists: NO
Related CWE: CVE-2023-XXXX (Example CVE)
CPE: a:7stickynotes:7_sticky_notes:1.9
Platforms Tested: Windows
2023
7 Sticky Notes v1.9 – OS Command Injection
7 Sticky Notes v1.9 is vulnerable to OS command injection. By manipulating the 'Action' field in the 'Alarms' tab, an attacker can execute arbitrary commands on the system. An attacker can set a malicious command as an alarm action, leading to the execution of the command when the alarm triggers.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user inputs to prevent command injection attacks. Additionally, limiting the functionalities of the application to only necessary operations can reduce the attack surface.