Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-7788
HistoryDec 11, 2020 - 11:15 a.m.

Code injection

2020-12-1111:15:00
PRIOn knowledge base
www.prio-n.com
8

9.2 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.4%

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

CPENameOperatorVersion
debian_linuxeq9.0
inilt1.3.6