Advertisement






SecZetta NEProfile 3.3.11 Remote Code Execution

CVE Category Price Severity
CVE-2020-12854 CWE-XXX Not specified High
Author Risk Exploitation Type Date
Not specified High Remote 2020-07-16
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H 0.07537 0.42568

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020070081

Below is a copy:

SecZetta NEProfile 3.3.11 Remote Code Execution
Exploit Title: NEProfile - Remote Code Execution
Date: 5/13/2020
Vendor Homepage: https://seczetta.com
Software Link: https://seczetta.com/product/ne-profile
Version: 3.3.11
Tested on: 3.3.11
Exploit Author: Josh Sheppard
Exploit Contact: ghost () a t undervurse dot_com
Exploit Technique: Remote
CVE ID: CVE-2020-12854

1. Description

A remote code execution vulnerability was identified in SecZetta's NEProfile product. Authenticated remote adversaries can invoke code execution upon uploading a carefully crafted jpg as part of the profile avatar.

The issue affects version 3.3.11 and has not been tested on other versions of the product.

2. Disclosure Timeline

5/4/20 - Discovery and Exploitation
5/12/20 - Vendor Notified
6/18/20 - Patch / Hotfix Created

3. Mitigation

Apply hotfix provided by vendor


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum