PT-2026-47343 · Git+1 · Openbullet2
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenBullet2 versions prior to 0.3.3
Description
Authenticated users can execute arbitrary C# code on the server host by creating or modifying job configurations. This is possible because the plain C# execution mode does not implement reference filtering or API restrictions, allowing an attacker to access the file system, spawn processes, and invoke arbitrary .NET APIs with the privileges of the process user.
Recommendations
Update to a version newer than 0.3.2.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbullet2