#VU48734 Prototype Pollution in systeminformation - CVE-2020-26245
Published: November 27, 2020 / Updated: December 1, 2020
systeminformation
Sebastian Hildebrandt
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper input validation in service parameter strings that are passed to si.inetChecksite(). A remote attacker can overwrite the properties and functions of an object, which can lead to executing arbitraty commands.