CVE-2020-13448
high · 8.8QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
8.8
CVSS
17.4%
EPSS (exploit prob.)
97th
EPSS percentile
2020-06-01
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| quickbox | quickbox | <= 2.5.5 |
| quickbox | quickbox | <= 2.1.8 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-13448