CVE-2020-13694

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
01/06/2020
Last modified:
02/06/2020

Description

In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which means that the www-data user can execute arbitrary OS commands via the mysql -e option.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:quickbox:quickbox:*:*:*:*:community:*:*:* 2.5.5 (including)
cpe:2.3:a:quickbox:quickbox:*:*:*:*:pro:*:*:* 2.1.8 (including)


References to Advisories, Solutions, and Tools