High severity8.8NVD Advisory· Published Aug 28, 2018· Updated Jun 17, 2026
CVE-2018-15529
CVE-2018-15529
Description
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- Range: <6.1.0-5263
- osv-coords8 versionspkg:apk/chainguard/keycloakpkg:apk/chainguard/keycloak-bitnami-compatpkg:apk/chainguard/keycloak-compatpkg:apk/chainguard/keycloak-iamguarded-compatpkg:apk/wolfi/keycloakpkg:apk/wolfi/keycloak-bitnami-compatpkg:apk/wolfi/keycloak-compatpkg:apk/wolfi/keycloak-iamguarded-compat
< 0+ 7 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/149065/Mutiny-Monitoring-Appliance-Command-Injection.htmlnvdThird Party AdvisoryVDB Entry
- github.com/doddr/Security-Advisories/tree/master/Mutiny/CVE-2018-15529nvdThird Party Advisory
- doddsecurity.com/135/remote-command-execution-on-the-monitoring-appliances/nvd
- www.mutiny.com/mutiny-support/release-summary/nvd
News mentions
0No linked articles in our index yet.