Arbitrary OS Command Execution in OpenNDS Captive Portal

Arbitrary OS Command Execution in OpenNDS Captive Portal

CVE-2023-38316 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests.

Learn more about our Web Application Penetration Testing UK.