← back
CVE-2023-31465observed exploitation

CVE-2023-31465

52Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 44%
from disclosure to weapon
Published on NVDJul 26
VulnCheck+131d
exploitation probability
44%top 1% of all CVEs
observed exploitation
yesVulnCheck
An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server.
Affected products
n/a · n/a