vendor:
eMerge E3
by:
LiquidWorm
10.0
CVSS
CRITICAL
Remote Code Execution
20
CWE
Product Name: eMerge E3
Affected Version From: 1.00-06
Affected Version To: 1.00-06
Patch Exists: YES
Related CWE: CVE-2019-7256
CPE: a:linear_solutions:emerge_e3:1.00-06
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: NA
2018
eMerge E3 1.00-06 – Remote Code Execution
An unauthenticated attacker can execute arbitrary code on the eMerge E3 1.00-06 system by sending a specially crafted HTTP request to the card_scan.php page. This vulnerability is due to insufficient input validation of the No and ReaderNo parameters. An attacker can exploit this vulnerability by sending a malicious HTTP request to the vulnerable system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update their systems to the latest version.