Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-7361

Опубликовано: 06 авг. 2020
Источник: nvd
CVSS3: 9.6
CVSS3: 8.8
CVSS2: 9
EPSS Средний

Описание

The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:easycorp:zentao_pro:*:*:*:*:*:*:*:*
Версия до 8.8.2 (включая)

EPSS

Процентиль: 97%
0.35969
Средний

9.6 Critical

CVSS3

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78
CWE-78

Связанные уязвимости

github
больше 3 лет назад

The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands will run in an elevated SYSTEM context on the underlying Windows operating system.

EPSS

Процентиль: 97%
0.35969
Средний

9.6 Critical

CVSS3

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78
CWE-78