vendor:
GitList
by:
Kacper Szurek, Shelby Pace
N/A
CVSS
HIGH
Argument Injection
Argument Injection
CWE
Product Name: GitList
Affected Version From: 0.6.0
Affected Version To: 0.6.0
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: php
2018
GitList v0.6.0 Argument Injection Vulnerability
This module exploits an argument injection vulnerability in GitList v0.6.0. The vulnerability arises from GitList improperly validating input using the php function 'escapeshellarg'.
Mitigation:
Update to a version of GitList that properly validates user input.