9.8
CVSSv3

CVE-2020-15922

Published: 24/07/2020 Updated: 01/01/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

There is an OS Command Injection in Mida eFramework 2.9.0 that allows an malicious user to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

midasolutions eframework

Vendor Advisories

Check Point Reference: CPAI-2020-4129 Date Published: 28 Feb 2024 Severity: Critical ...

Exploits

Mida eFramework version 289 suffers from a remote code execution vulnerability ...