peter bassill · operator
$ cve CVE-2020-7356 JSON

CVE-2020-7356

10.0
CRITICAL · CVSS 3.1 · EPSS 14% (pctl 96)

Patch early

EPSS 14% — above the 10% action threshold.

Description

CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS14.01% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2020-08-06
Last modified2026-06-17

Affected (1)

VendorProduct
cayintechxpost

References

→ the Explorer  ·  watch your stack  ·  NVD