N-Reporter and N-Cloud, products of the N-Partner, have an OS Command Injection vulnerability. Remote attackers with normal user privilege can execute arbitrary system commands by manipulating user inputs on a specific page.
No PoCs from references.
- https://github.com/fkie-cad/nvd-json-data-feeds