vendor:
Mida eFramework
by:
elbae
9.8
CVSS
CRITICAL
OS Command Injection Remote Code Execution Vulnerability (RCE)
78
CWE
Product Name: Mida eFramework
Affected Version From: <= 2.9.0
Affected Version To: 2.9.0
Patch Exists: YES
Related CWE: CVE-2020-15920
CPE: 2.9.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
Mida eFramework 2.9.0 – Remote Code Execution
A vulnerability exists in Mida eFramework 2.9.0 which allows an attacker to execute arbitrary code on the vulnerable system. This is due to the application not properly validating user-supplied input before using it in an OS command. An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable application. Successful exploitation of this vulnerability could result in arbitrary code execution on the vulnerable system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to the latest version of the software.