vendor:
liveSite
by:
tmrswrr
8.1
CVSS
CRITICAL
Remote Code Execution
RCE-78
CWE
Product Name: liveSite
Affected Version From: 2019.1
Affected Version To: 2019.1
Patch Exists: NO
Related CWE:
CPE: a:livesite:livesite:2019.1
Platforms Tested: Web
2024
liveSite Version : 2019.1 Campaigns Remote Code Execution
The vulnerability in liveSite Version 2019.1 allows an attacker to execute arbitrary code remotely. By creating a campaign with a specific payload, an attacker can view sensitive system information like the contents of '/etc/passwd'.
Mitigation:
To mitigate this vulnerability, it is recommended to update liveSite to a patched version and avoid executing untrusted code.