Логотип exploitDog
bind:CVE-2020-25557
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-25557

Количество 2

Количество 2

nvd логотип

CVE-2020-25557

около 5 лет назад

In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-rf6m-wqqh-49rx

больше 3 лет назад

In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-25557

In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.

CVSS3: 8.8
6%
Низкий
около 5 лет назад
github логотип
GHSA-rf6m-wqqh-49rx

In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.

6%
Низкий
больше 3 лет назад

Уязвимостей на страницу