ZeroHour

CVE-2020-11722

CVSS 3.1
9.8 critical
EPSS
4%p90
Published
()
Modified
Description

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

Vendors
dungeon crawl stone soup project
Products
dungeon crawl stone soup
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.