Code Injection in jsen - CVE-2020-7777
Published: November 23, 2020 / Updated: November 30, 2020
jsen
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in "Function.apply();". A remote administrator can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.