CVE-2023-47104

Critical
|9.8
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to inject malicious commands into the tinyfiledialogs application by using special characters in titles and messages, potentially leading to unauthorized actions on the system. It affects versions before 3.15.0 and takes advantage of a previous fix that didn't fully address the issue.

Technical Description

tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double quote characters.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$13,000($5K-$15K)
Vendor Response
Grade FPatched in 861 days

Quick Information

Published

Oct 30, 2023

over 2 years ago

Last Modified

Mar 10, 2026

28 days ago

Vendor

vareille

Product

tinyfiledialogs