CVE-2019-7670

Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.

Date published : 2019-07-01

http://packetstormsecurity.com/files/155271/FlexAir-Access-Control-2.3.38-Remote-Root.html

https://applied-risk.com/labs/advisories