OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://openpanel.com/docs/changelog/0.3.5/#%EF%B8%8F-security-fixes | broken link |
https://packetstorm.news/files/id/188915/ | exploit |