CVE-2023-47104
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to inject malicious commands into the tinyfiledialogs application by using special characters in titles and messages, potentially leading to unauthorized actions on the system. It affects versions before 3.15.0 and takes advantage of a previous fix that didn't fully address the issue.
Technical Description
tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double quote characters.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Oct 30, 2023
over 2 years ago
Last Modified
Mar 10, 2026
28 days ago
Vendor
vareille
Product
tinyfiledialogs