CyberRota Analysis
AI-GeneratedThe vulnerability exists in the "quick question" admin feature of the interchange project, allowing unauthenticated users to inject and execute arbitrary Perl code on the server in default installations. This poses a critical remote code execution risk, particularly if the AllowGlobal directive is enabled, which can expand the attacker's capabilities. Organizations using the interchange project should prioritize addressing this vulnerability to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is configured for the catalog being accessed.CTOR]