VulnerabilityModified
CVE-2023-30258
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
CRITICAL 9.8EPSS 94.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 94.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 94.25% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78, CWE-77
- Affected
- magnussolution/magnusbilling
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/175672/MagnusBilling-Remote-Command-Execution.html
- https://eldstal.se/advisories/230327-magnusbilling.htmlExploit, Mitigation, Third Party Advisory
- https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2023-30258.md
- https://github.com/magnussolution/magnusbilling7/commit/ccff9f6370f530cc41ef7de2e31d7590a0fdb8c3Patch
- http://packetstormsecurity.com/files/175672/MagnusBilling-Remote-Command-Execution.html
- https://eldstal.se/advisories/230327-magnusbilling.htmlExploit, Mitigation, Third Party Advisory
- https://github.com/magnussolution/magnusbilling7/commit/ccff9f6370f530cc41ef7de2e31d7590a0fdb8c3Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.