CVE-2020-14950: OS Command Injection
Published Jun 21, 2020
·Updated
aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a modified /system?action=ServiceAdmin request (start, stop, or restart) to the setting menu of Sotfware Store.
Affected Software
1 affected component
aaPanel aaPanel<=6.6.6
Event History
Jun 21, 2020
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
Description
Frequently Asked Questions
1
What is CVE-2020-14950?
CVE-2020-14950 is a vulnerability in aaPanel through 6.6.6 that allows remote authenticated users to execute arbitrary commands via shell metacharacters.
2
How does CVE-2020-14950 work?
CVE-2020-14950 works by exploiting shell metacharacters in a modified /system?action=ServiceAdmin request to the setting menu of Software Store in aaPanel.
3
What is the severity of CVE-2020-14950?
CVE-2020-14950 has a severity rating of 8.8 (high).
4
What software versions are affected by CVE-2020-14950?
Versions up to and including 6.6.6 of aaPanel are affected by CVE-2020-14950.
5
How can I fix CVE-2020-14950?
To fix CVE-2020-14950, update aaPanel to a version higher than 6.6.6.