High severity8.8NVD Advisory· Published Jan 20, 2023· Updated Jun 17, 2026
CVE-2023-23596
CVE-2023-23596
Description
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- jc21/NGINX Proxy Managerdescription
- Range: <=2.9.19
Patches
Vulnerability mechanics
References
2- advisory.dw1.io/57nvdExploitThird Party Advisory
- github.com/NginxProxyManager/nginx-proxy-manager/blob/4f10d129c20cc82494b95cc94b97f859dbd4b54d/backend/internal/access-list.jsnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.