First published: Tue Aug 25 2020(Updated: )
Cellopoint Cellos v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject and remotely execute arbitrary command to manipulate the system.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Cellopoint Cellos | =4.1.10-build20190922 |
Update to v4.1.10 Build 20200210 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2020-17384.
The severity of CVE-2020-17384 is critical.
Cellopoint Cellos v4.1.10 Build 20190922 is affected by this vulnerability.
With the cookie of the system administrator, attackers can inject and remotely execute arbitrary commands to manipulate the system.
Currently, there is no known fix available for CVE-2020-17384. It is recommended to contact the software vendor for updates or patches.