dst-admin kickPlayer command injection
CVE-2023-0647
7.5HIGH
What is CVE-2023-0647?
A command injection vulnerability exists in the dst-admin product version 1.5.0, where manipulation of the userId argument in the file /home/kickPlayer allows an attacker to execute arbitrary commands remotely. This exploit, once publicly disclosed, poses a significant security risk and underscores the importance of updating software to mitigate such issues.
Affected Version(s)
dst-admin 1.5.0
