Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-27696 | jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5. |
Thu, 03 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-03T14:42:26.783Z
Reserved: 2023-01-15T00:00:00.000Z
Link: CVE-2023-23596
Updated: 2024-08-02T10:35:33.296Z
Status : Modified
Published: 2023-01-20T08:15:12.670
Modified: 2025-04-03T15:15:46.947
Link: CVE-2023-23596
No data.
OpenCVE Enrichment
No data.
EUVD