A lack of authentication vulnerability exists in the HTTP...
Critical severity
Unreviewed
Published
Dec 20, 2024
to the GitHub Advisory Database
•
Updated Dec 20, 2024
Description
Published by the National Vulnerability Database
Nov 21, 2024
Published to the GitHub Advisory Database
Dec 20, 2024
Last updated
Dec 20, 2024
A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
References