Arbitrary Code Execution Vulnerability in Etherpad 1.5.x and 1.6.x

Arbitrary Code Execution Vulnerability in Etherpad 1.5.x and 1.6.x

CVE-2018-9327 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB).

Learn more about our Cis Benchmark Audit For Mongodb.