Arbitrary Code Execution in HummerRisk Software
CVE-2023-43449
8.8HIGH
What is CVE-2023-43449?
A security vulnerability has been identified in HummerRisk software that allows authenticated attackers to leverage a flaw in the LicenseService component. By crafting specific requests, an attacker can execute arbitrary code on affected versions of HummerRisk, including those from v1.10 to v1.4.1. This vulnerability exposes systems to potential unauthorized access and significant security risks. Users are advised to take immediate action to mitigate potential threats by patching affected versions and reviewing security measures.
