CVE-2023-25759: Uniguest Tripleplay
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivileged OS level commands via a crafted request payload.
Affected products
- Uniguest Tripleplay: version 3.4.0 only
Published 2023-04-19. Last modified 2026-06-17.