Vulnerability Description
Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the software.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubilling | Ubilling | 1.0.9 |
Related Weaknesses (CWE)
References
- https://drive.google.com/file/d/1iLMFSbY8x1CXIf0uFntovY6yZ7N24dQA/view?usp=shariExploitIssue TrackingThird Party Advisory
- https://drive.google.com/file/d/1smOjvenPB-nE0PyIxnfujCT4KcxxkeWV/view?usp=shariExploitThird Party Advisory
- https://gist.github.com/mhaskar/bfa9c2c799fca6697bcc6a213d08cb3eExploitThird Party Advisory
- https://drive.google.com/file/d/1iLMFSbY8x1CXIf0uFntovY6yZ7N24dQA/view?usp=shariExploitIssue TrackingThird Party Advisory
- https://drive.google.com/file/d/1smOjvenPB-nE0PyIxnfujCT4KcxxkeWV/view?usp=shariExploitThird Party Advisory
- https://gist.github.com/mhaskar/bfa9c2c799fca6697bcc6a213d08cb3eExploitThird Party Advisory
FAQ
What is CVE-2020-29311?
CVE-2020-29311 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the software.
How severe is CVE-2020-29311?
CVE-2020-29311 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-29311?
Check the references section above for vendor advisories and patch information. Affected products include: Ubilling Ubilling.