CVE-2020-11107

HIGH

XAMPP <7.2.29, <7.3.16, <7.4.4 - Command Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.

Exploits (4)

exploitdb WORKING POC
by Salman Asad · powershelllocalwindows
https://www.exploit-db.com/exploits/50337
nomisec WRITEUP 32 stars
by S1lkys · poc
https://github.com/S1lkys/CVE-2020-11107
nomisec WRITEUP 3 stars
by andripwn · poc
https://github.com/andripwn/CVE-2020-11107
nomisec WORKING POC
by Mohnad-AL-saif · poc
https://github.com/Mohnad-AL-saif/Mohnad-AL-saif-CVE-2020-11107-XAMPP-Local-Privilege-Escalation

Scores

CVSS v3 8.8
EPSS 0.3891
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
apachefriends/xampp < 7.2.29
Published Apr 02, 2020
Tracked Since Feb 18, 2026