← Back

CVE-2020-11107

nvd nist
Published: Apr 2, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.

Affected (3)

Products: Apachefriends: Xampp
1 product
Xampp
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Apachefriends
Before 7.2.29
From 7.3.0 to 7.3.16
From 7.4.0 to 7.4.4
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (4)

Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.