PT-2020-16220 · Apache+1 · Groovy+2

Kai Zhao

·

Published

2020-10-06

·

Updated

2022-02-09

·

CVE-2020-25802

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Crafter CMS versions prior to 3.0.27 Crafter CMS versions prior to 3.1.7
Description The issue is related to improper control of dynamically-managed code resources in Crafter Studio, allowing authenticated developers to execute OS commands via Groovy scripting.
Recommendations For versions prior to 3.0.27, update to version 3.0.27 or later. For versions prior to 3.1.7, update to version 3.1.7 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25802
GHSA-WQ3V-3GRQ-6F86

Affected Products

Crafter Cms
Crafter Studio
Groovy