CVE-2020-6144: Code Injection
Published Sep 1, 2020
·Updated
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line 121 in install/Step5.php allows for injection of PHP code into the Data.php file that it writes. An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
1 affected component
OS4ED openSIS=7.4
Event History
Sep 1, 2020
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-6144?
CVE-2020-6144 is a remote code execution vulnerability in the install functionality of OS4Ed openSIS 7.4.
2
How severe is CVE-2020-6144?
CVE-2020-6144 has a severity rating of 9.8 (critical).
3
Which software version is affected by CVE-2020-6144?
CVE-2020-6144 affects OS4Ed OpenSIS 7.4.
4
How does CVE-2020-6144 work?
CVE-2020-6144 allows for injection of PHP code into the Data.php file through the username variable in install/Step5.php.
5
Is there a fix available for CVE-2020-6144?
No fix information is available at this time. Please refer to the vendor's website or security advisories for updates.