Command injection in SafePay - CVE-2019-6736
Published: January 31, 2019
SafePay
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists within the processing of tiscript due to insufficient validation of user-supplied input when processing the System.Exec method. A remote attacker can trick the victim into visiting a malicious page or opening a malicious file, inject arbitrary commands and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise