TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T13:22:29.264Z
Reserved: 2020-07-06T00:00:00
Link: CVE-2020-15568
No data.
Status : Modified
Published: 2021-01-30T05:15:12.493
Modified: 2024-11-21T05:05:45.750
Link: CVE-2020-15568
No data.
OpenCVE Enrichment
No data.
Weaknesses