PT-2020-15708 · Minetime · Minetime
4Nqr34Z
+1
·
Published
2020-08-24
·
Updated
2020-08-31
·
CVE-2020-24364
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MineTime versions prior to 1.9
Description
The issue allows arbitrary command execution via the notes field in a meeting, which could lead to remote code execution (RCE) via a meeting invite.
Recommendations
For versions prior to 1.9, update to version 1.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the notes field in meetings to minimize the risk of exploitation.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minetime