PT-2026-90953 · Cym1102+1 · Nginxwebui
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
cym1102 nginxWebUI versions prior to 4.4.3
Description
Remote code injection is possible through the manipulation of the
url argument within the MainController.autoUpdate() function located in the /adminPage/main/autoUpdate file.Recommendations
As a temporary workaround, restrict access to the
/adminPage/main/autoUpdate endpoint or disable the MainController.autoUpdate() function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Code Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nginxwebui