vendor:
Tiny Tiny RSS
by:
Daniel Neagaru & Benjamin Nadarević
9.8
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: Tiny Tiny RSS
Affected Version From: all before 2020-09-16
Affected Version To: 2020-09-16
Patch Exists: YES
Related CWE: CVE-2020-25787
CPE: a:fox/tt-rss
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: default docker installation method
2020
Tiny Tiny RSS – Remote Code Execution
A vulnerability in Tiny Tiny RSS before 2020-09-16 allows remote attackers to execute arbitrary code by leveraging the ability to inject arbitrary data into a malicious RSS feed. This is due to the lack of proper input validation in the 'config.php' file. An attacker can craft a malicious RSS feed containing a specially crafted link which can be used to execute arbitrary code on the vulnerable system.
Mitigation:
Upgrade to Tiny Tiny RSS version 2020-09-16 or later.