tinyfiledialogs (aka tiny file dialogs) before 3.15.0...
Critical severity
Unreviewed
Published
Oct 30, 2023
to the GitHub Advisory Database
•
Updated Sep 10, 2024
Description
Published by the National Vulnerability Database
Oct 30, 2023
Published to the GitHub Advisory Database
Oct 30, 2023
Last updated
Sep 10, 2024
tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double quote characters.
References