CVE-2020-8102
Summary
| CVE | CVE-2020-8102 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-22 10:15:00 UTC |
| Updated | 2020-06-26 15:31:00 UTC |
| Description | Improper Input Validation vulnerability in the Safepay browser component of Bitdefender Total Security 2020 allows an external, specially crafted web page to run remote commands inside the Safepay Utility process. This issue affects Bitdefender Total Security 2020 versions prior to 24.0.20.116. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bitdefender | Total Security 2020 | All | All | All | All |
| Application | Bitdefender | Total Security 2020 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Insufficient URL sanitization and validation in Safepay Browser (VA-8631) - Bitdefender | MISC | www.bitdefender.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Wladimir Palant
There are currently no legacy QID mappings associated with this CVE.