peter bassill · operator
$ cve CVE-2013-3632 JSON

CVE-2013-3632 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 57.1% (pctl 99)

Patch early

A public exploit exists.

Description

The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS57.11% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2014-09-29
Last modified2026-06-16

Affected (1)

VendorProduct
openmediavaultopenmediavault

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD