Vulnerability Description
Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sqreen | Php Microagent | < 1.16.0 |
Related Weaknesses (CWE)
References
- https://blog.sqreen.com/vulnerability-disclosure-finding-a-vulnerability-in-sqreExploitVendor Advisory
- https://blog.sqreen.com/vulnerability-disclosure-finding-a-vulnerability-in-sqreExploitVendor Advisory
FAQ
What is CVE-2020-25490?
CVE-2020-25490 is a vulnerability with a CVSS score of 7.3 (HIGH). Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine.
How severe is CVE-2020-25490?
CVE-2020-25490 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-25490?
Check the references section above for vendor advisories and patch information. Affected products include: Sqreen Php Microagent.