RULE(RULE ID:337968)

Rule General Information
Release Date: 2024-04-29
Rule Name: Juice Shop Chatbot Command Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Juice Shop is a Web application that covers OWASP Top10 vulnerabilities. The Juice Shop Chatbot program has a remote command execution vulnerability. If a user submits commands through the browser, the commands can be executed remotely because the server does not filter the execution functions.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.