CVE-2020-11107: High severity bitnami xampp vulnerability
Published Apr 2, 2020
·Updated
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
Affected Software
4 affected components
Apachefriends Xampp<7.2.29
Apachefriends Xampp>=7.3.0<7.3.16
Apachefriends Xampp>=7.4.0<7.4.4
Microsoft Windows
Event History
Apr 2, 2020
CVE Published
via MITRE·05:44 PM
Data Sourced
via MITRE·05:44 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-11107.
2
What is the severity of CVE-2020-11107?
The severity of CVE-2020-11107 is high (8.8).
3
What is the affected software for CVE-2020-11107?
The affected software for CVE-2020-11107 is XAMPP versions 7.2.29, 7.3.x (7.3.0 to 7.3.16), and 7.4.x (7.4.0 to 7.4.4) on Windows.
4
How can an unprivileged user exploit CVE-2020-11107?
An unprivileged user can change a .exe configuration in xampp-contol.ini to enable arbitrary command execution.
5
Are there any fixes or patches available for CVE-2020-11107?
Yes, the fix for CVE-2020-11107 is available in XAMPP versions 7.2.29, 7.3.16, and 7.4.4. It is recommended to update to the latest version.