ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to change the title and then execute it as commands.
                
            References
                    | Link | Resource | 
|---|---|
| https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e | Third Party Advisory | 
| https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md | Release Notes | 
| https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e | Third Party Advisory | 
| https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md | Release Notes | 
Configurations
                    History
                    19 Feb 2025, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-116 | 
Information
                Published : 2023-03-28 20:15
Updated : 2025-02-19 19:15
NVD link : CVE-2022-46387
Mitre link : CVE-2022-46387
CVE.ORG link : CVE-2022-46387
JSON object : View
Products Affected
                cmder
- cmder
maximus5
- conemu
CWE
                