PT-2020-19768 · Systeminformation · Systeminformation

Effectrenan

·

Published

2020-10-26

·

Updated

2021-07-21

·

CVE-2020-7752

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions systeminformation versions prior to 4.27.11
Description This issue affects the systeminformation package, allowing an attacker to perform Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.
Recommendations For versions prior to 4.27.11, upgrade to version 4.27.11 or later to resolve the issue. As a temporary workaround for versions that cannot be upgraded, check or sanitize service parameter strings that are passed to si.inetChecksite().

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7752
GHSA-94XH-2FMC-XF5J
SNYK-JS-SYSTEMINFORMATION-1021909

Affected Products

Systeminformation