Tiandy Easy7 Integrated Management Platform OS Command Injection Vulnerability
Vulnerability
An OS command injection vulnerability has been identified in Tiandy Easy7 Integrated Management Platform version 7.17.0. The issue arises in the file '/Easy7/rest/systemInfo/updateDbBackupInfo', where manipulation of the 'week' parameter allows for command injection. This vulnerability can be exploited remotely, and the exploit is publicly available.
Impact
Exploitation of this vulnerability allows for OS command injection, where an attacker can execute arbitrary commands on the server.
Reproduction
To reproduce this vulnerability, send a POST request to '/Easy7/rest/systemInfo/updateDbBackupInfo' with the 'week' parameter manipulated to include a command injection payload. The injected command will be executed on the server, and the output can be directed to a file in the root directory.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
