A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19907
Reference (s):
- https://github.com/mitre/caldera/issues/462

