PoC Index

CVE-2020-36772

MEDIUM 4.4EPSS 0.4%

CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files of certain file formats outside the CageFS environment.

CVSS v3.1
4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS v3.1
4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS
0.38% chance of exploitation in the next 30 days, 31th percentile
Published
2024-01-22
Updated
2025-05-30

Proof-of-concept exploits (2)

References

Related