← All CVEs

CVE-2020-13448

high · 8.8

QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.

8.8
CVSS
17.4%
EPSS (exploit prob.)
97th
EPSS percentile
2020-06-01
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
quickboxquickbox<= 2.5.5
quickboxquickbox<= 2.1.8

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-13448