Back to search
CVE-2024-53992
Published: Dec 2, 2024
Modified: Dec 5, 2024
PUBLISHED
Description
unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malicious commands that are executed through subprocess.Popen with shell=True. Attackers can exploit this vulnerability using a crafted archive name, password, or video name. This vulnerability is fixed in 7.0.3a.
| Vendor | Product | Versions |
|---|---|---|
EDM115 | unzip-bot | affected < 7.0.3a |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now