CVE-2023-45158
9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.69% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-10-16 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| web2py | web2py |
References
- http://web2py.com/
- http://web2py.com/init/default/download
- https://github.com/web2py/web2py/commit/936e2260b0c34c44e2f3674a893e96d2a7fad0a3
- https://jvn.jp/en/jp/JVN80476432/
- http://web2py.com/
- http://web2py.com/init/default/download
- https://github.com/web2py/web2py/commit/936e2260b0c34c44e2f3674a893e96d2a7fad0a3
- https://jvn.jp/en/jp/JVN80476432/
→ the Explorer · watch your stack · NVD