9.8
CVSSv3

CVE-2020-15920

Published: 24/07/2020 Updated: 20/01/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 892
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

There is an OS Command Injection in Mida eFramework up to and including 2.9.0 that allows an malicious user to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

midasolutions eframework

Exploits

Mida eFramework version 290 suffers from a remote code execution vulnerability ...