A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ``ssmctl-client`` command.
This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS.
Loading...