Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-29007

Опубликовано: 15 апр. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mediawiki:score:*:*:*:*:*:mediawiki:*:*
Версия до 0.3.0 (включая)

EPSS

Процентиль: 92%
0.07456
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94
CWE-94

Связанные уязвимости

CVSS3: 9.8
github
почти 3 года назад

The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.

EPSS

Процентиль: 92%
0.07456
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94
CWE-94