A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. This affects an unknown part of the file contrib/iSenWeb/trans_result.php. The manipulation of the argument input1 leads to os command injection.

This vulnerability is uniquely identified as CVE-2023-6309. The attack can only be done within the local network. Furthermore, there is an exploit available.