Vulnerability Details CVE-2020-11766
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.043
EPSS Ranking 88.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2020-11766
-
cpe:2.3:a:avantfax:avantfax:3.3.0
-
cpe:2.3:a:avantfax:avantfax:3.3.3
-
cpe:2.3:a:avantfax:avantfax:3.3.4
-
cpe:2.3:a:avantfax:avantfax:3.3.5
-
cpe:2.3:a:ifax:hylafax:0.2.0