What the vulnerability does
01Description
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
Explanation of Vulnerability in Simple Terms
QA Analytics versions up to 5.2.0.0 contain a code injection vulnerability that allows unauthenticated attackers to execute arbitrary code on affected systems over the network. No user interaction is required. The vulnerability affects the entire system and can compromise confidentiality, integrity, and availability.
What an attacker can do
Run arbitrary code on the server without authentication.
Potential impact on your site
Complete system compromise: attackers can read data, modify content, disable the service, or pivot to other systems.
Conditions required to exploit
Network access to the QA Analytics instance; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities