Remote Command Execution Vulnerability in dst-admin by Libestor
CVE-2023-43270
9.8CRITICAL
What is CVE-2023-43270?
A remote command execution vulnerability has been identified in dst-admin version 1.5.0, which allows attackers to execute arbitrary commands on the server. This exploitation occurs through improper handling of the userId parameter in the /home/playerOperate endpoint, posing a significant risk to system integrity and confidentiality. Users should promptly update to the latest version to mitigate this threat. Further details can be accessed through the linked reference.
