nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-28870 CVE-2020-28870
CRITICAL
InoERP 0.7.2 - Remote Code Execution (Unauthenticated)
Record summary
CVE-2020-28870 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBInoERP 0.7.2 - Remote Code Execution (Unauthenticated)ExploitDB exploitby Lyhin\'s LabNot analyzed1 file
References
2exploit-db.com
https://www.exploit-db.com/exploits/48946