| TVN ID | TVN-202006002 |
|---|---|
| CVE ID | CVE-2020-17384 |
| CVSS | 7.2 (High) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| Affected Products | CelloOS v4.1.10 Build 20190922 |
| Description | Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject and remotely execute arbitrary command to manipulate the system. |
| Solution | Update to v4.1.10 Build 20200210 or higher. |
| Credit | Cyku Hong from DEVCORE (https://devco.re) |
| Public Date | 2020-08-27 |
