Vulnerability Details CVE-2020-10806
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.023
EPSS Ranking 83.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-10806
-
cpe:2.3:a:ez:ez_publish-kernel:*
-
cpe:2.3:a:ez:ez_publish-kernel:6.0.0
-
cpe:2.3:a:ez:ez_publish-kernel:7.0.0
-
cpe:2.3:a:ez:ez_publish-legacy:*
-
cpe:2.3:a:ez:ez_publish-legacy:2017.0
-
cpe:2.3:a:ez:ez_publish-legacy:2019.0