A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability by sending a specially crafted HTTP PUT request to upload a malicious file (e.g., a reverse shell script). Once uploaded, the attacker can trigger the execution of arbitrary commands on the target system, allowing for remote code execution. This could lead to escalation of privileges depending on the privileges of the web server process. The attack does not require physical access and can be conducted remotely, posing a significant risk to the confidentiality and integrity of the system.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Twisted
Twisted twisted |
|
Vendors & Products |
Twisted
Twisted twisted |
Tue, 05 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Tue, 05 Aug 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability by sending a specially crafted HTTP PUT request to upload a malicious file (e.g., a reverse shell script). Once uploaded, the attacker can trigger the execution of arbitrary commands on the target system, allowing for remote code execution. This could lead to escalation of privileges depending on the privileges of the web server process. The attack does not require physical access and can be conducted remotely, posing a significant risk to the confidentiality and integrity of the system. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-05T00:00:00.000Z
Updated: 2025-08-05T20:02:00.472Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50688

Updated: 2025-08-05T20:01:56.274Z

Status : Awaiting Analysis
Published: 2025-08-05T18:15:32.083
Modified: 2025-08-05T21:06:25.813
Link: CVE-2025-50688

No data.