9.8
CVSSv3

CVE-2020-5847

Published: 16/03/2020 Updated: 12/07/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unraid up to and including 6.8.0 allows Remote Code Execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

unraid unraid

Exploits

This Metasploit module exploits two vulnerabilities affecting Unraid 680 An authentication bypass is used to gain access to the administrative interface, and an insecure use of the extract PHP function can be abused for arbitrary code execution as root ...

Github Repositories

CVE-2020-5847 exploit written in python

CVE-2020-5847-exploit Author: @1Exovant Description WORK IN PROGRESS This is a python script for exploiting CVE-2020-5847, CVE-2020-5849 This module exploits two vulnerabilities affecting Unraid 680 An authentication bypass is used to gain access to the administrative interface, and an insecure use of the extract PHP function can be abused for arbitrary code execution as