PT-2026-85274 · Moos Ivp · Moos-Ivp
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY MOOS messages containing backticks or command substitution syntax to execute arbitrary commands as the iSay process user.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moos-Ivp