Vulnerability Description
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
CVSS Score
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iblsoft | Online Weather | < 4.3.5 |
Related Weaknesses (CWE)
References
- https://github.com/dawid-czarnecki/public-vulnerabilities/tree/master/Online_WeaThird Party Advisory
- https://zigrin.com/advisories/online-weather-command-injection-in-querybcp-metho
- https://github.com/dawid-czarnecki/public-vulnerabilities/tree/master/Online_WeaThird Party Advisory
- https://zigrin.com/advisories/online-weather-command-injection-in-querybcp-metho
FAQ
What is CVE-2020-9406?
CVE-2020-9406 is a vulnerability with a CVSS score of 9.8 (CRITICAL). IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
How severe is CVE-2020-9406?
CVE-2020-9406 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-9406?
Check the references section above for vendor advisories and patch information. Affected products include: Iblsoft Online Weather.