Security Advisory

CVE-2020-26124

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-10-02 08:28:03
Last updated 2024-08-04 15:49:07
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.