CVE-2020-13768 Information

Description

In MiniShare before 1.4.2 there is a stack-based buffer overflow via an HTTP PUT request which allows an attacker to achieve arbitrary code execution a similar issue to CVE-2018-19861 CVE-2018-19862 and CVE-2019-17601. NOTE: this product is discontinued.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://github.com/sartlabs/OSCE-Prep/blob/9a9d2471a9de09457f970be4ea1b57a74d26705a/My20CVEs/Minishare_BOF_PUT.py

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: