CVE-2020-26124: Code Injection
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because jsonencodesafe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26124?
CVE-2020-26124 is classified as a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2020-26124?
To fix CVE-2020-26124, you should upgrade to OpenMediaVault version 4.1.36 or 5.5.12 or later.
What is the impact of exploiting CVE-2020-26124?
Exploiting CVE-2020-26124 can result in authenticated PHP code injection that allows an attacker to execute arbitrary commands on the system.
Which versions of OpenMediaVault are affected by CVE-2020-26124?
OpenMediaVault versions before 4.1.36 and from 5.0.0 to 5.5.12 are affected by CVE-2020-26124.
Who is primarily affected by CVE-2020-26124?
Users and administrators of vulnerable OpenMediaVault installations are primarily affected by CVE-2020-26124.