Vulnerability Description
Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gridx Project | Gridx | 1.3 |
References
- http://mayoterry.com/file/cve/Remote_Code_Execution_Vulnerability_in_gridx_latesExploitThird Party Advisory
- https://github.com/oria/gridx/issues/433ExploitIssue TrackingThird Party Advisory
- http://mayoterry.com/file/cve/Remote_Code_Execution_Vulnerability_in_gridx_latesExploitThird Party Advisory
- https://github.com/oria/gridx/issues/433ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-19625?
CVE-2020-19625 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.
How severe is CVE-2020-19625?
CVE-2020-19625 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-19625?
Check the references section above for vendor advisories and patch information. Affected products include: Gridx Project Gridx.