PT-2020-13367 · Mylittleadmin · Mylittleadmin
Published
2020-05-15
·
Updated
2022-04-26
·
CVE-2020-13166
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MyLittleAdmin version 3.8
Description
The management tool in the affected software allows remote attackers to execute arbitrary code because the
machineKey is hardcoded in the web.config file, which is the same for all customers' installations. This hardcoded machineKey can be used to send serialized ASP code.Recommendations
For MyLittleAdmin version 3.8, consider changing the hardcoded
machineKey in the web.config file to a unique value for each installation as a temporary workaround. Restrict access to the management tool to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mylittleadmin