CVE Database
/

CVE-2024-53992

Back to search

CVE-2024-53992

Published: Dec 2, 2024

Modified: Dec 5, 2024

PUBLISHED

Description

unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malicious commands that are executed through subprocess.Popen with shell=True. Attackers can exploit this vulnerability using a crafted archive name, password, or video name. This vulnerability is fixed in 7.0.3a.

VendorProductVersions

EDM115

unzip-bot

affected
< 7.0.3a

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now