CVE-2020-7849

A vulnerability of uPrism.io CURIX(Video conferecing solution) could allow an unauthenticated attacker to execute arbitrary code. This vulnerability is due to insufficient input(server domain) validation. An attacker could exploit this vulnerability through crafted URL.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:uprism:curix:1.3.6:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:37

Type Values Removed Values Added
References () https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35903 - Third Party Advisory () https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35903 - Third Party Advisory
CVSS v2 : 6.8
v3 : 8.8
v2 : 6.8
v3 : 8.0

Information

Published : 2021-02-17 14:15

Updated : 2024-11-21 05:37


NVD link : CVE-2020-7849

Mitre link : CVE-2020-7849

CVE.ORG link : CVE-2020-7849


JSON object : View

Products Affected

uprism

  • curix

microsoft

  • windows
CWE
CWE-20

Improper Input Validation