CVE-2019-13640

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
17/07/2019
Last modified:
07/11/2023

Description

In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command execution via a crafted name within an RSS feed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qbittorrent:qbittorrent:*:*:*:*:*:*:*:* 4.1.7 (excluding)