CVSS v3
8.8
HIGH
EPSS Score
36.5 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
Technical details
- Published
- 2020-04-02
- Exploit-DB
- EDB-50337
Frequently asked questions
What is CVE-2020-11107?
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
Is CVE-2020-11107 actively exploited?
Active exploitation of CVE-2020-11107 has not been confirmed. The EPSS score is 36.5%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2020-11107?
CVE-2020-11107 has a CVSS v3 base score of 8.8 (HIGH severity).
Is CVE-2020-11107 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2020 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).