Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
Threat-Mapped Scoring
Score: 1.8
Priority: P4 - Informational (Low)
S9 – Sabotage of System/App
EPSS
Score: 0.01681 Percentile:
0.81392
CVSS Scoring
CVSS v3.1 Score: 9.9
Severity: CRITICAL
Mapped CWE(s)
CWE-77
: Improper Neutralization of Special Elements used in a Command ('Command Injection')