PT-2020-17406 · Klog · Klog Server

Published

2020-12-27

·

Updated

2021-02-18

·

CVE-2020-35729

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions KLog Server version 2.4.1
Description The issue allows OS command injection via shell metacharacters in the user parameter of the "actions/authenticate.php" API endpoint.
Recommendations For KLog Server version 2.4.1, avoid using the user parameter in the "actions/authenticate.php" endpoint until the issue is resolved. Consider restricting access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35729

Affected Products

Klog Server