CVE-2020-7752: Command Injection
Impact command injection vulnerability
Patches Problem was fixed with a shell string sanitation fix. Please upgrade to version >= 4.27.11
Workarounds If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite()
References Are there any links users can visit to find out more?
For more information If you have any questions or comments about this advisory: Open an issue in systeminformation
Other sources
This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7752?
The severity of CVE-2020-7752 is high with a CVSS score of 8.8.
How can I fix CVE-2020-7752?
To fix CVE-2020-7752, you need to upgrade the systeminformation package to version 4.27.11 or later.
Is there a workaround for CVE-2020-7752 if I can't upgrade the systeminformation package?
Yes, if you cannot upgrade the systeminformation package, you can check or sanitize service parameter strings that are passed to si.inetChecksite().
What is the impact of CVE-2020-7752?
CVE-2020-7752 is a command injection vulnerability that could allow an attacker to execute arbitrary commands on the affected system.
Where can I find more information about CVE-2020-7752?
You can find more information about CVE-2020-7752 at the following references: [Link 1](https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-94xh-2fmc-xf5j), [Link 2](https://github.com/sebhildebrandt/systeminformation/commit/931fecaec2c1a7dcc10457bb8cd552d08089da61), [Link 3](https://www.npmjs.com/package/systeminformation).