PT-2020-13652 · Quickbox+1 · Quickbox Community Edition+2
S1Gh
·
Published
2020-06-01
·
Updated
2020-06-02
·
CVE-2020-13694
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
QuickBox Community Edition versions 2.5.5 and earlier
QuickBox Pro Edition versions 2.1.8 and earlier
Description
The issue allows the local www-data user to execute sudo mysql without a password. This means the www-data user can execute arbitrary OS commands via the mysql -e option.
Recommendations
For QuickBox Community Edition versions 2.5.5 and earlier, update to a version where this issue is fixed.
For QuickBox Pro Edition versions 2.1.8 and earlier, update to a version where this issue is fixed.
As a temporary workaround, consider restricting the
www-data user's access to the mysql command until a patch is available.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quickbox Community Edition
Quickbox Pro Edition
Mysql Server