PT-2026-67488 · Clearos · Clearos
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ClearOS version 7.9
Description
The Log Viewer component contains an OS command injection flaw. Authenticated attackers can execute arbitrary commands by submitting unsanitized input through the
filter parameter, which is interpolated directly into a shell command within File.php. By using command substitution payloads in the filter parameter, attackers can execute commands as the webconfig user and subsequently escalate privileges to root due to default NOPASSWD sudo permissions granted to that user.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearos