Beveiligingsadvies

CVE-2020-11084

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-07-14 21:15:13
Laatst bijgewerkt 2024-08-04 11:21:14
Toegewezen door GitHub_M
CVSS-score 6.4
Status PUBLISHED

Beschrijving

In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPear which may change, damage, or steal data (files) from the PC.