A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
References
| Link | Resource |
|---|---|
| http://mirth.com | Product |
| http://nextgen.com | Product |
| http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command-Execution.html | |
| https://www.ihteam.net/advisory/mirth-connect | Exploit Third Party Advisory |
Configurations
History
31 Jan 2024, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2023-08-03 03:15
Updated : 2024-01-31 18:15
NVD link : CVE-2023-37679
Mitre link : CVE-2023-37679
CVE.ORG link : CVE-2023-37679
JSON object : View
Products Affected
nextgen
- mirth_connect
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
