Логотип exploitDog
bind:CVE-2020-15252
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15252

Количество 2

Количество 2

nvd логотип

CVE-2020-15252

больше 5 лет назад

In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that may lead to arbitrary code execution. This is patched in XWiki 12.5 and XWiki 11.10.6.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-5hv6-mh8q-q9v8

больше 5 лет назад

RCE in XWiki

CVSS3: 8.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15252

In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that may lead to arbitrary code execution. This is patched in XWiki 12.5 and XWiki 11.10.6.

CVSS3: 8.5
3%
Низкий
больше 5 лет назад
github логотип
CVSS3: 8.5
3%
Низкий
больше 5 лет назад

Уязвимостей на страницу