vendor:
Mida eFramework
by:
elbae
9.8
CVSS
CRITICAL
OS Command Injection RCE
78
CWE
Product Name: Mida eFramework
Affected Version From: <= 2.8.9
Affected Version To: <= 2.8.9
Patch Exists: YES
Related CWE: CVE-2020-15922
CPE: 2.8.9
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
Mida eFramework 2.8.9 – Remote Code Execution
Mida eFramework 2.8.9 is vulnerable to OS Command Injection RCE in PDC/pages/network.php, which allows an attacker to execute arbitrary commands on the vulnerable system. This vulnerability can be exploited by sending a maliciously crafted POST request to the vulnerable page. The exploit can be used to gain a reverse shell on the vulnerable system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to the latest version of the software.