CVE-2020-10789
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell met
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.
CRITICAL · CVSS 9.8
EPSS 0.00593
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0