Summary
The Backup module accepts user-controlled filenames that may contain malicious characters, potentially resulting in command injection as the asterisk user.
Authentication with a known username is required.
Common Vulnerabilities and Exposures (CVE)
Requested
GitHub Security Advisory (GHSA)
GHSA-65g4-v227-g8m3
Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)
G - Green
Link to Published GHSA with More Details
Highlights
![]()