CVE-2021-29393

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
04/02/2022
Last modified:
09/02/2022

Description

Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:globalnorthstar:northstar_club_management:6.3:*:*:*:*:*:*:*