Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Very High
CVE-2013-3632
Disclosure Date: September 29, 2014 (last updated October 05, 2023)
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.
1
Attacker Value
Unknown
CVE-2020-26124
Disclosure Date: October 02, 2020 (last updated February 22, 2025)
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.
0
Attacker Value
Unknown
CVE-2017-1000065
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.
0