What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in POSIMYTH Nexter Extension.This issue affects Nexter Extension: from n/a through 2.0.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in POSIMYTH Nexter Extension.This issue affects Nexter Extension: from n/a through 2.0.3.
Explanation of Vulnerability in Simple Terms
The Nexter Extension for POSIMYTH contains a code injection vulnerability in versions up to 2.0.3. An authenticated administrator can inject and execute arbitrary code on the site. The vulnerability requires high-level privileges and does not require user interaction. Impact extends beyond the vulnerable component, affecting confidentiality, integrity, and availability.
What an attacker can do
Run arbitrary code on the site with full system access.
Potential impact on your site
A compromised admin account can execute code, steal data, modify content, or take the site offline.
Conditions required to exploit
Attacker must have administrator-level access to the affected extension.
Key dates
External resources
Related vulnerabilities