CVE-2020-13448
HIGHQuickBox <2.5.5-2.1.8 - Command Injection
Title source: llmDescription
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
Exploits (1)
Scores
CVSS v3
8.8
EPSS
0.3917
EPSS Percentile
97.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (2)
quickbox/quickbox
< 2.1.8
quickbox/quickbox
< 2.5.5
Published
Jun 01, 2020
Tracked Since
Feb 18, 2026