PT-2020-13231 · Code42 · Code42

Published

2020-07-07

·

Updated

2021-07-21

·

CVE-2020-12736

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Code42 versions 7.0.4 and earlier
Description The issue allows for possible remote code execution when an administrator creates a local user via a Code42-generated email and modifies the email invitation content. If the administrator enters template language code in the subject line, it could be interpreted by the email generation services, potentially resulting in server-side code injection.
Recommendations For versions 7.0.4 and earlier, consider disabling the email invitation feature for local user creation until a patch is available. Restrict access to the email generation services to minimize the risk of exploitation. Avoid using template language code in the subject line of email invitations to prevent potential server-side code injection.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12736

Affected Products

Code42