RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-36749.json"