peter bassill · operator
$ cve CVE-2020-13166 JSON

CVE-2020-13166 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 77.6% (pctl 100)

Patch early

A public exploit exists.

Description

The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS77.64% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploityes
Published2020-05-19
Last modified2026-06-17

Affected (1)

VendorProduct
mylittletoolsmylittleadmin

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD