#VU64736 OS Command Injection in VShell - CVE-2022-28054
Published: June 28, 2022 / Updated: June 28, 2022
VShell
Van Dyke Technologies
Description
The vulnerability allows a remote user to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input when a trigger action is configured to run a script. A remote user can pass a specially crafted value to the trigger and execute arbitrary commands on the system.