VulnerabilityModified
CVE-2020-26806
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.
HIGH 8.8EPSS 5.97%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.97% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- objectplanet/opinio
- Source
- cve@mitre.org
References
- https://packetstormsecurity.com/files/163709/ObjectPlanet-Opinio-7.13-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://www.objectplanet.com/opinio/changelog.htmlRelease Notes, Vendor Advisory
- https://packetstormsecurity.com/files/163709/ObjectPlanet-Opinio-7.13-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://www.objectplanet.com/opinio/changelog.htmlRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.