Back to overview

CVE-2022-23603

CRITICAL
9.9
CVSS 3.1
Description
iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f43aa user input is not properly sanitized and code injection is possible. Users are advised to upgrade as soon as is possible. There are no known workarounds for this issue.

Metadata

CVE ID
CVE-2022-23603
State
PUBLISHED
Assigner
GitHub_M
Reserved
2022-01-19 00:00 UTC
Published
2022-02-01 10:43 UTC
Last updated
2025-05-05 16:25 UTC
Primary CWE
CWE-116
CWE-116 Improper Encoding or Escaping of Output
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-116 adp CWE-116 Improper Encoding or Escaping of Output
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
Back to overview