Vulnerability Description
iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize image file paths leading to OS level command injection. This issue has been patched in commit cdcd48b. Users are advised to upgrade.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Itunesrpc-Remastered Project | Itunesrpc-Remastered | - |
Related Weaknesses (CWE)
References
- https://github.com/bildsben/iTunesRPC-Remastered/commit/cdcd48bbc44009ddcbd07a80PatchThird Party Advisory
- https://github.com/bildsben/iTunesRPC-Remastered/security/advisories/GHSA-mjv7-rThird Party Advisory
- https://github.com/bildsben/iTunesRPC-Remastered/commit/cdcd48bbc44009ddcbd07a80PatchThird Party Advisory
- https://github.com/bildsben/iTunesRPC-Remastered/security/advisories/GHSA-mjv7-rThird Party Advisory
FAQ
What is CVE-2022-23611?
CVE-2022-23611 is a vulnerability with a CVSS score of 8.1 (HIGH). iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize image file paths leading to OS level command injectio...
How severe is CVE-2022-23611?
CVE-2022-23611 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23611?
Check the references section above for vendor advisories and patch information. Affected products include: Itunesrpc-Remastered Project Itunesrpc-Remastered.