CVE-2022-41158

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
25/11/2022
Last modified:
27/06/2023

Description

Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploit the vulnerability to execute or inject malicious code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eyoom:eyoom_builder:*:*:*:*:*:*:*:* 4.5.3 (including)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*