CVE-2020-12736

HIGHCVSS 7.2/10EPSS 2.03%

Last modified

CVE-2020-12736 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-generated email, the administrator has the option to modify content for the email invitation. EPSS estimates a 2.03% chance of exploitation in the next 30 days.

Description

Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-generated email, the administrator has the option to modify content for the email invitation. If the administrator entered template language code in the subject line, that code could be interpreted by the email generation services, potentially resulting in server-side code injection.

Metrics

CVSS 3.1
7.2/10

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.03%

78.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Code42Code42<= 7.0.4

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-12736?
Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-generated email, the administrator has the option to modify content for the email invitation. If the administrator entered template language code in the subject line, that code could be interpreted by the email generation services, potentially resulting in server-side code injection.
How severe is CVE-2020-12736?
CVE-2020-12736 has a CVSS score of 7.2/10 (HIGH severity). The EPSS model estimates a 2.03% probability of exploitation in the next 30 days.
How do I fix CVE-2020-12736?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-12736?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST