Lucene search

K
cvelistKrcertCVELIST:CVE-2020-7841
HistoryNov 17, 2020 - 1:04 p.m.

CVE-2020-7841 TOBESOFT XPLATFORM arbitrary hta file execution vulnerability

2020-11-1713:04:12
CWE-20
krcert
www.cve.org
4
cve-2020-7841
tobesoft
xplatform
input validation
arbitrary file execution

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.003

Percentile

71.9%

Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://

CNA Affected

[
  {
    "platforms": [
      "Windows"
    ],
    "product": "XPLATFORM XPlatformLib922.dll",
    "vendor": "TOBESOFT",
    "versions": [
      {
        "lessThan": "9.2.2.250(2019-08-27)",
        "status": "affected",
        "version": "9.2.2.250",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.003

Percentile

71.9%

Related for CVELIST:CVE-2020-7841