CVE-2021-36667

Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
Configurations

Configuration 1

cpe:2.3:a:druva:insync_client:*:*:*:*:*:macos:*:*

Information

Published : 2022-07-12 02:15

Updated : 2022-07-20 04:22


NVD link : CVE-2021-36667

Mitre link : CVE-2021-36667

Products Affected
CWE