CVE-2020-25466: SSRF
Published Oct 23, 2020
·Updated
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
Affected Software
1 affected component
crmeb crmeb=3.0
Event History
Oct 23, 2020
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-25466?
CVE-2020-25466 is considered a critical vulnerability due to its capability to remotely execute arbitrary code on the server.
2
How do I fix CVE-2020-25466?
To fix CVE-2020-25466, update CRMEB 3.0 to the latest patched version released by the vendor.
3
What types of attacks can CVE-2020-25466 facilitate?
CVE-2020-25466 can facilitate various attacks including remote code execution and unauthorized data access.
4
Is CVE-2020-25466 present in CRMEB versions other than 3.0?
CVE-2020-25466 specifically affects CRMEB version 3.0, and no other versions are mentioned.
5
Can CVE-2020-25466 be exploited without authentication?
Yes, CVE-2020-25466 can be exploited without authentication, making it particularly dangerous if left unpatched.