7.2
CVSSv3

CVE-2020-14421

Published: 18/06/2020 Updated: 27/01/2023
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

aaPanel up to and including 6.6.6 allows remote authenticated users to execute arbitrary commands via the Script Content box on the Add Cron Job screen.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aapanel aapanel

Exploits

aaPanel version 666 suffers from an authenticated privilege escalation vulnerability ...

Github Repositories

aapanel 6.6.6 - (Authenticated) Remote Code Execution

aapanel aapanel 666 - CVE-2020-14950 Description : allows remote authenticated users to execute arbitrary commands via the setting menu of Sotfware Store Affected version : All <= 666 Information To make this PoC, I just installed the software using docker-compose Vulnerability Type : Remote command execution (Authenticated RCE) POC Go to Software Store, click o