CVE-2020-13448

HIGH

QuickBox <2.5.5-2.1.8 - Command Injection

Title source: llm

Description

QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.

Exploits (1)

exploitdb WORKING POC
by s1gh · pythonwebappsphp
https://www.exploit-db.com/exploits/48536

Scores

CVSS v3 8.8
EPSS 0.3917
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
quickbox/quickbox < 2.1.8
quickbox/quickbox < 2.5.5
Published Jun 01, 2020
Tracked Since Feb 18, 2026