stamparm Maltrail Command Injection Vulnerability Allowing Remote Code Execution
Vulnerability
A command injection vulnerability allowing unauthenticated remote code execution exists in stamparm Maltrail versions through 0.54. The issue arises from improper handling of user input in the username parameter of POST requests to the /login endpoint. This vulnerability allows attackers to inject arbitrary operating system commands, which are executed with the same privileges as the Maltrail process.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the server where Maltrail is running.
Reproduction
To reproduce this vulnerability, send a POST request to the /login endpoint with a payload that includes injected commands in the username parameter. The injected commands will be executed on the server.
Remediation
Users can update to Maltrail version 0.55 or later, where this vulnerability has been fixed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
