CVE-2020-11766: OS Command Injection
Published May 19, 2020
·Updated
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
Affected Software
2 affected components
iFAX HylaFAX>=0.2.0<0.2.5
AvantFAX AvantFAX>=3.3.0<3.3.6
Event History
May 19, 2020
CVE Published
via MITRE·07:27 PM
Data Sourced
via MITRE·07:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-11766?
The severity of CVE-2020-11766 is rated as important due to its potential for command injection attacks.
2
How do I fix CVE-2020-11766?
To fix CVE-2020-11766, upgrade iFAX AvantFAX to version 3.3.6 or higher and HylaFAX Enterprise Web Interface to version 0.2.5 or above.
3
What impacts does CVE-2020-11766 have on affected systems?
CVE-2020-11766 allows authenticated users to execute arbitrary commands on the server through the sendfax.php script.
4
What versions of AvantFAX are affected by CVE-2020-11766?
AvantFAX versions between 3.3.0 and 3.3.6 are affected by CVE-2020-11766.
5
What versions of HylaFAX Enterprise Web Interface are affected by CVE-2020-11766?
HylaFAX Enterprise Web Interface versions between 0.2.0 and 0.2.5 are affected by CVE-2020-11766.