CVE-2023-49213: Ironmansoftware PowerShell Universal

High severity, CVSS 8.8. EPSS: 2.1% chance of exploitation in the next 30 days.

The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.

Affected products

  • Ironmansoftware PowerShell Universal: from 3.0.0, before 3.10.2 (fixed in 3.10.2); from 4.1.0, before 4.1.10 (fixed in 4.1.10); version 4.2.0 only

Published 2023-11-23. Last modified 2026-06-17.