📦

score

Vendor: mediawiki

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 24.53% Exploit Prob.
Latest CVE CVE-2020-29007 Apr 15

Security Vulnerability Index

Page 1 / 1
9.8 CVSS
CVE-2020-29007
RCE Exploit Found

The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.

EPSS: 24.53%