{"id":"CVE-2023-49102","details":"NZBGet 21.1 allows authenticated remote code execution because the unarchive programs (7za and unrar) preserve executable file permissions. An attacker with the Control capability can execute a file by setting the value of SevenZipCommand or UnrarCmd. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","modified":"2026-08-12T03:30:08.734538253Z","published":"2023-11-22T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49102.json"},"references":[{"type":"WEB","url":"https://nzbget.net/download"},{"type":"WEB","url":"https://sec.maride.cc/posts/nzbget/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49102.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49102"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nzbget/nzbget","events":[{"introduced":"b0d35f9a0985c4dd5987c51ab4007c0abae3b505"},{"last_affected":"b0d35f9a0985c4dd5987c51ab4007c0abae3b505"}],"database_specific":{"cpe":"cpe:2.3:a:nzbget:nzbget:21.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"21.1"},{"last_affected":"21.1"}],"source":"CPE_STRING"}}],"versions":["21.1","v21.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-49102.json"}}],"schema_version":"1.9.0"}