Required CVE Record Information
Description
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in MarketingFire Widget Options allows OS Command Injection.This issue affects Widget Options: from n/a through 4.1.0.
CWE 1 Total
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
9.9 | CRITICAL | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Credits
- Tran Nguyen Bao Khanh VCI - VNPT (Patchstack Alliance) finder
- Phan Trong Quan - VNPT Cyber Immunity (Patchstack Alliance) other