- Description
- An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.
- Source
- security@progress.com
- NVD status
- Analyzed
- Products
- loadmaster
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:*",
"matchCriteriaId": "09E601FC-0D63-44B7-8726-DA512D075139",
"versionEndExcluding": "7.2.54.9",
"versionStartIncluding": "7.2.49.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:progress:loadmaster:*:*:*:*:ga:*:*:*",
"matchCriteriaId": "F95CC892-C725-49BE-AC30-3AB2C1547517",
"versionEndExcluding": "7.2.59.3",
"versionStartIncluding": "7.2.55.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:progress:loadmaster:7.1.35.10:*:*:*:mt:*:*:*",
"matchCriteriaId": "8F615B26-D735-4A95-9D04-D434B61CFB38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:progress:loadmaster:7.2.48.10:*:*:*:lts:*:*:*",
"matchCriteriaId": "8DDDA906-6A2C-4662-B3EC-6406BC32370D",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]