ZeroHour

CVE-2020-15920

PoC ×3
CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
Modified
Description

There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.

Vendors
midasolutions
Products
eframework
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.