CVE-2023-49213
23.11.2023, 22:15
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.
Vendor | Product | Version |
---|---|---|
ironmansoftware | powershell_universal | 3.0.0 ≤ 𝑥 < 3.10.2 |
ironmansoftware | powershell_universal | 4.1.0 ≤ 𝑥 < 4.1.10 |
ironmansoftware | powershell_universal | 4.2.0 |
𝑥
= Vulnerable software versions