CVE-2020-28865: High severity powerjob vulnerability
Published Jun 16, 2022
·Updated
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.
Affected Software
1 affected component
Powerjob PowerJob<=3.2.2
Remediation
Patch Available
Event History
Jun 16, 2022
CVE Published
via MITRE·08:36 PM
Data Sourced
via MITRE·08:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-28865?
CVE-2020-28865 is considered a high-severity vulnerability due to its potential to allow unauthorized password changes.
2
How do I fix CVE-2020-28865?
To fix CVE-2020-28865, upgrade PowerJob to version 3.2.3 or later.
3
What types of attacks can exploit CVE-2020-28865?
CVE-2020-28865 can be exploited to perform unauthorized password changes on user accounts.
4
Which software versions are affected by CVE-2020-28865?
CVE-2020-28865 affects PowerJob versions up to and including 3.2.2.
5
Is CVE-2020-28865 a local or remote vulnerability?
CVE-2020-28865 is a remote vulnerability that can be exploited without physical access to the system.