Back to Database
Status published
High
CVE-2020-7866
Tobesoft XPLATFORM Arbitrary Command Execution Vulnerability
Vulnerability Description
When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper input validation
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-7866
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Thanks to Jeongun Baek for reporting this vulnerability
References
More from Tobesoft
View All →CVE-2020-7857
A vulnerability of XPlatform could allow an unauthenticated attacker to...
High
7.5
CVE-2020-7853
TOBESOFT XPLATFORM Out-of-Bounds Read/Write Vulnerabilities
Medium
5.5
CVE-2020-7821
Tobesoft NEXACRO14/17 ExCommonApiV13 Arbitrary Code Execution Vulnerability
High
7.8
CVE-2020-7820
Tobesoft NEXACRO14/17 ExCommonApiV13 Arbitrary Code Execution Vulnerability
High
7.8
CVE-2020-7806
Tobesoft Xplatform ActiveX File Download Vulnerability
High
7.8
Affected Vendor
Tobesoft
View all reports →Affected Software
XPLATFORM
Vulnerable Versions:
unspecified
Timeline
Official Publish:
July 20th, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H