ZeroHour

CVE-2020-7788

PoC
CVSS 3.1
9.8 critical
EPSS
4%p89
Published
()
Modified
Description

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

Vendors
ini projectdebian
Products
ini, debian linux
Weakness
CWE-1321
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.