CVE-2019-11364: Prophecyinternational Snare Central

High severity, CVSS 7.2. EPSS: 2.2% chance of exploitation in the next 30 days.

An OS Command Injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to inject arbitrary OS commands via the ServerConf/DataManagement/DiskManager.php FORMNAS_share parameter.

Affected products

Published 2019-08-29. Last modified 2026-06-17.