NZBGet 21.1 allows authenticated remote code execution because the unarchive programs (7za and unrar) preserve executable file permissions. An attacker with the Control capability can execute a file by setting the value of SevenZipCommand or UnrarCmd. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://nzbget.net/download |
|
| https://sec.maride.cc/posts/nzbget/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T21:46:29.049Z
Reserved: 2023-11-21T00:00:00
Link: CVE-2023-49102
No data.
Status : Modified
Published: 2023-11-22T22:15:08.867
Modified: 2024-11-21T08:32:49.773
Link: CVE-2023-49102
No data.
OpenCVE Enrichment
No data.
Weaknesses