OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark.
Software | From | Fixed in |
---|---|---|
centrinity / centrinity_firstclass_desktop_client | 8.0 | 8.0.x |