CVE-2023-23596
Last modified
CVE-2023-23596 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. EPSS estimates a 15.20% chance of exploitation in the next 30 days.
Description
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jc21 | Nginx Proxy Manager | <= 2.9.19 |
References
- https://advisory.dw1.io/57Exploit, Third Party Advisory
- https://advisory.dw1.io/57Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23596?
How severe is CVE-2023-23596?
How do I fix CVE-2023-23596?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-2359The Slider Revolution WordPress plugin through 6.6.12 does n…8.8
- CVE-2023-23590Mercedes-Benz XENTRY Retail Data Storage 7.8.1 allows remote…7.5
- CVE-2023-23591The Logback component in Terminalfour before 8.3.14.1 allows…4.9
- CVE-2023-23592WALLIX Access Manager 3.x through 4.0.x allows a remote atta…7.5
- CVE-2023-23594An authentication bypass vulnerability in the web client int…9.8
- CVE-2023-23595BlueCat Device Registration Portal 2.2 allows XXE attacks th…7.5
- CVE-2023-23597A compromised web child process could disable web security o…6.5
- CVE-2023-23598Due to the Firefox GTK wrapper code's use of text/plain for …6.5
- CVE-2023-23599When copying a network request from the developer tools pane…6.5
- CVE-2023-2360Sensitive information disclosure due to CORS misconfiguratio…7.5
- CVE-2023-23600Per origin notification permissions were being stored in a w…6.5
- CVE-2023-23601Navigations were being allowed when dragging a URL from a cr…6.5
Are you affected by CVE-2023-23596?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
