#VU29388 Code Injection in Gnu - CVE-2020-15011
Published: June 30, 2020
Gnu
GNU
Description
The vulnerability allows a remote attacker to inject arbitrary content.
The vulnerability exists due to improper input validation within the Cgi/private.py private archive login page. A remote attacker can send a specially crafted request and inject arbitrary content.
Successful exploitation of the vulnerability requires that the roster visibility (private_roster) setting is 'Anyone'.