Vulnerability Details CVE-2020-20294
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 75.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-20294
-
cpe:2.3:a:cmswing:cmswing:1.3.8