Sploitus

CVE-2020-29007

1 known exploit for CVE-2020-29007

The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.

Affected products
The Score Extension
Mediawiki Score
≤ 0.3.0
CVSS 3.1
9.8 CRITICAL
EPSS
2.3% (82th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2023-04-15
CVE-2020-29007 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2020-29007

Proof-of-concept code and exploit modules indexed by Sploitus