BeyondTrust Privileged Remote Access (PRA) and Remote...
Critical severity
Unreviewed
Published
Sep 5, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Sep 5, 2023
Published to the GitHub Advisory Database
Sep 5, 2023
Last updated
Apr 4, 2024
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote attacker to execute underlying operating system commands within the context of the site user. This issue is fixed in version 23.2.3.
References