An issue in Eramba Limited Eramba Enterprise v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.
                
            References
                    | Link | Resource | 
|---|---|
| http://eramba.com | Broken Link | 
| https://trovent.github.io/security-advisories/TRSA-2303-01/TRSA-2303-01.txt | |
| https://trovent.io/security-advisory-2303-01/ | Exploit Third Party Advisory | 
| https://www.eramba.org | |
| http://eramba.com | Broken Link | 
| https://trovent.github.io/security-advisories/TRSA-2303-01/TRSA-2303-01.txt | |
| https://trovent.io/security-advisory-2303-01/ | Exploit Third Party Advisory | 
| https://www.eramba.org | 
Configurations
                    History
                    21 Nov 2024, 08:09
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://eramba.com - Broken Link | |
| References | () https://trovent.github.io/security-advisories/TRSA-2303-01/TRSA-2303-01.txt - | |
| References | () https://trovent.io/security-advisory-2303-01/ - Exploit, Third Party Advisory | |
| References | () https://www.eramba.org - | 
05 Aug 2023, 03:50
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 8.8  | 
| References | (MISC) http://eramba.com - Broken Link | |
| References | (MISC) https://trovent.io/security-advisory-2303-01/ - Exploit, Third Party Advisory | |
| CWE | CWE-94 | |
| CPE | cpe:2.3:a:eramba:eramba:3.19.1:*:*:*:*:*:*:* | 
03 Aug 2023, 02:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-08-03 02:15
Updated : 2024-11-21 08:09
NVD link : CVE-2023-36255
Mitre link : CVE-2023-36255
CVE.ORG link : CVE-2023-36255
JSON object : View
Products Affected
                eramba
- eramba
 
CWE
                
                    
                        
                        CWE-94
                        
            Improper Control of Generation of Code ('Code Injection')
