CVE-2020-11819

CRITICAL

Rukovoditel - Path Traversal

Title source: rule

Description

In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution.

Exploits (3)

exploitdb WORKING POC
by coiffeur · bashwebappsphp
https://www.exploit-db.com/exploits/49238
exploitdb WORKING POC
by danyx07 · pythonwebappsphp
https://www.exploit-db.com/exploits/48784
nomisec WORKING POC
by danyx07 · poc
https://github.com/danyx07/PoC-RCE-Rukovoditel

Scores

CVSS v3 9.8
EPSS 0.2700
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
rukovoditel/rukovoditel 2.5.2
Published Apr 16, 2020
Tracked Since Feb 18, 2026