Remote Code Execution in NorthStar Club Management 6.3 via cominput.jsp and comoutput.jsp

Remote Code Execution in NorthStar Club Management 6.3 via cominput.jsp and comoutput.jsp

CVE-2021-29393 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.

Learn more about our User Device Pen Test.