Record summary

CVE-2022-45639 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.

Description

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List

Proofs of concept

1

Catalogued exploits

ExploitDBsleuthkit 4.11.1 - Command InjectionExploitDB exploitby Dino BarlattaniNot analyzed1 file
ExploitDB

PoC details

References

4