Lucene search

K
cvelistMitreCVELIST:CVE-2020-13695
HistoryJun 01, 2020 - 5:45 p.m.

CVE-2020-13695

2020-06-0117:45:16
mitre
www.cve.org

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.8%

In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information via a grep of a /root/*.db or /etc/shadow file.

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.8%

Related for CVELIST:CVE-2020-13695