RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.
| Software | From | Fixed in |
|---|---|---|
| sourcefabric / rpi-jukebox-rfid | 2.3.0 | 2.3.0.x |