vendor:
QuickBox Pro
by:
s1gh
8.8
CVSS
HIGH
Authenticated Remote Code Execution
78
CWE
Product Name: QuickBox Pro
Affected Version From: <= 2.1.8
Affected Version To: <= 2.1.8
Patch Exists: YES
Related CWE: CVE-2020-13448
CPE: 2.3:a:quickbox:quickbox_pro:2.1.8
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian 9
2020
QuickBox Pro 2.1.8 – Authenticated Remote Code Execution
An authenticated low-privileged user can exploit a command injection vulnerability to get code-execution as www-data and escalate privileges to root due to weak sudo rules.
Mitigation:
Ensure that all users have the least privilege necessary to perform their job functions. Ensure that all users are aware of the security risks associated with command injection attacks.