Lucene search

K
cvelistMitreCVELIST:CVE-2020-14159
HistoryJun 15, 2020 - 6:21 p.m.

CVE-2020-14159

2020-06-1518:21:59
mitre
www.cve.org

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.0%

By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before 2019.12.337, 2020 before 2020.1.53, 2020.2 before 2020.2.85, 2020.3 before 2020.3.114, 2020.4 before 2020.4.143, and 2020.5 before 2020.5.178.

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.0%

Related for CVELIST:CVE-2020-14159