Freewill iFIS (aka SMART Trade) 20.01.01.04 allows OS Command Injection via shell metacharacters to a report page.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://www.freewillsolutions.com/smart-trade-ifis | product |
https://www.kb.cert.org/vuls/id/947701 | third party advisory us government resource |
https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2023/MNDT-2023-0012.md | third party advisory |