CVE-2022-23915

Description

The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.633

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-23915,CVE-2022-24727 are fixed in Python-weblate 4.11.1Windows
Vulnerabilities CVE-2022-23915,CVE-2022-24727 are fixed in Python-weblate for linux 4.11.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234