CVE-2020-11598

CRITICAL

CIPPlanner CIPAce < 9.1 - Unauthenticated Remote Code Execution via Upload.ashx

Title source: llm
STIX 2.1

Description

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0251
EPSS Percentile 82.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306 CWE-434
Status published
Products (1)
cipplanner/cipace < 9.1
Published Apr 06, 2020
Tracked Since Feb 18, 2026