TVN ID | TVN-202006002 |
---|---|
CVE ID | CVE-2020-17384 |
CVSS | 7.2 (High) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Affected Products | CelloOS v4.1.10 Build 20190922 |
Description | Cellopoint Cellos v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject and remotely execute arbitrary command to manipulate the system. |
Solution | Update to v4.1.10 Build 20200210 or higher. |
Credit | Cyku Hong from DEVCORE (https://devco.re) |
Public Date | 2020-08-27 |