PT-2020-13231 · Code42 · Code42
Published
2020-07-07
·
Updated
2021-07-21
·
CVE-2020-12736
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Code42 versions 7.0.4 and earlier
Description
The issue allows for possible remote code execution when an administrator creates a local user via a Code42-generated email and modifies the email invitation content. If the administrator enters template language code in the subject line, it could be interpreted by the email generation services, potentially resulting in server-side code injection.
Recommendations
For versions 7.0.4 and earlier, consider disabling the email invitation feature for local user creation until a patch is available. Restrict access to the email generation services to minimize the risk of exploitation. Avoid using template language code in the subject line of email invitations to prevent potential server-side code injection.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Code42