← Back to browse · API

CVE-2022-1509

Severity
CRITICAL
CVSS
9.9
EPSS
0.04589
Risk score
41.21
CISA KEV
No
PoC
No
Published
2022-04-28
Modified
2024-08-30
First seen
2026-08-07
Aliases
EUVD-2022-24809, GHSA-99WP-PQM6-2VH4
Products
hestiacp:hestiacp/hestiacp unspecified <1.5.12
Sources
euvd EUVD-2022-24809

Description

Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.

References