PT-2020-15254 · Zzz · Zzzphp

Y4Er

·

Published

2020-12-18

·

Updated

2021-07-21

·

CVE-2020-20298

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions zzzphp version 1.7.2
Description The issue is related to an eval injection vulnerability in the parserCommom method within the ParserTemplate class in zzz template.php. This vulnerability allows remote attackers to execute arbitrary commands.
Recommendations For zzzphp version 1.7.2, consider disabling the parserCommom method in the ParserTemplate class until a patch is available. Restrict access to the zzz template.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-20298

Affected Products

Zzzphp