Security Advisory

CVE-2020-11084

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-07-14 21:15:13
Last updated 2024-08-04 11:21:14
Assigner GitHub_M
State PUBLISHED

Description

In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPear which may change, damage, or steal data (files) from the PC.