Description


A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download and execute an arbitrary file via httpDownload function. A successful exploit could allow the attacker to hijack vulnerable system.

Related CPE's


Weaknesses



CWE-20


CWE-20

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-09-07T13:15:07.527Z

4 years ago

Last modified

2024-11-21T04:37:56.400Z

1 year ago