CVE-2020-20298: Code Injection
Published Dec 18, 2020
·Updated
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzztemplate.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
Affected Software
1 affected component
ZZZCMS zzzphp=1.7.2
Event History
Dec 18, 2020
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-20298.
2
What is the severity level of CVE-2020-20298?
CVE-2020-20298 has a severity level classified as critical.
3
What is the affected software version of CVE-2020-20298?
The affected software version of CVE-2020-20298 is zzzphp 1.7.2.
4
How does CVE-2020-20298 allow remote attackers to execute arbitrary commands?
CVE-2020-20298 allows remote attackers to execute arbitrary commands through an eval injection vulnerability in the parserCommon method in the ParserTemplate class in zzz_template.php.
5
Is there a fix available for CVE-2020-20298?
Yes, it is recommended to update zzzphp to a version that addresses CVE-2020-20298.