CVE-2020-19625 Information

Description

Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3 allows remote attackers to execute arbitrary code via crafted value to the $query parameter.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

http://mayoterry.com/file/cve/Remote_Code_Execution_Vulnerability_in_gridx_latest_version.pdf https://github.com/oria/gridx/issues/433

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: