← voltar
CVE-2020-7351highCWE-78

Fonality Trixbox CE Post-Authentication Command Injection

48Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendcvss 7.3epss 65%
da publicação à arma0 dias
Publicada no NVD1 de mai.
metasploit28 de abr.
probabilidade de exploração
65%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N