{"id":"CVE-2020-15920","aliases":[],"url":"https://o3.security/vulnerability/CVE-2020-15920","summary":"There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.","details":"There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.","published":"2020-07-24T00:58:51.000Z","modified":"2024-08-04T13:30:23.202Z","cvss":null,"epss":{"score":0.98239,"percentile":0.99911,"asOf":"2026-08-27"},"cisaKev":null,"exploitsKnown":5,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://elbae.github.io/jekyll/update/2020/07/14/vulns-01.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/158991/Mida-eFramework-2.9.0-Remote-Code-Execution.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/159194/Mida-Solutions-eFramework-ajaxreq.php-Command-Injection.html"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2024-08-04T13:30:23.202Z"}}