7.2

CVE-2020-35754

Exploit
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensolution ≫ Quick.Cart Version < 6.7
Opensolution ≫ Quick.Cms Version < 6.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.46% 0.952
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://packetstormsecurity.com/files/161189/Quick.CMS-6.7-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
https://opensolution.org/cms-system-quick-cms.html
Product
https://opensolution.org/security-fix-for-cart-and-cms%21-en-1136.html
https://secator.pl/index.php/2021/01/28/cve-2020-35754-authenticated-rce-in-quick-cms-and-quick-cart/
Third Party Advisory
Exploit