// For flags

CVE-2020-10786

 

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.

Una ejecuciĆ³n de comando remota en Vesta Control Panel versiones hasta la versiĆ³n 0.9.8-26, permite a cualquier usuario autentificado ejecutar comandos arbitrarios en el sistema por medio de trabajos cron.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-03-20 CVE Reserved
  • 2020-04-21 CVE Published
  • 2024-05-31 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-863: Incorrect Authorization
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
https://gitlab.com/snippets/1954764 2021-07-21
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Vestacp
Search vendor "Vestacp"
Vesta Control Panel
Search vendor "Vestacp" for product "Vesta Control Panel"
<= 0.9.8-26
Search vendor "Vestacp" for product "Vesta Control Panel" and version " <= 0.9.8-26"
-
Affected