Логотип exploitDog
bind:CVE-2026-20902
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-20902

Количество 2

Количество 2

nvd логотип

CVE-2026-20902

30 дней назад

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xx68-gfhf-pwvh

29 дней назад

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-20902

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.

CVSS3: 8
0%
Низкий
30 дней назад
github логотип
GHSA-xx68-gfhf-pwvh

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.

CVSS3: 8
0%
Низкий
29 дней назад

Уязвимостей на страницу