ZeroHour

CVE-2020-10580

PoC
CVSS 3.1
8.8 high
EPSS
4%p90
Published
()
Modified
Description

A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.

Vendors
invigo
Products
automatic device management
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.