ZeroHour

CVE-2020-24985

PoC
CVSS 3.1
8.1 high
EPSS
1%p64
Published
()
Modified
Description

An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads.

Vendors
quadbase
Products
espressdashboard
Weakness
CWE-829
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.