CVE-2020-7752
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: report@snyk.io (Secondary)
Description
This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.
Affected (1)
Products: Systeminformation: Systeminformation
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.27.11 |
References (6)
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Timeline
No history available yet.