CVE-2020-13661 is a high-severity vulnerability affecting Telerik Fiddler versions through 5.0.20202.18177, allowing remote attackers to execute arbitrary programs. This is achieved by manipulating a hostname with specific trailing characters, which, when combined with a user interactively selecting the "Open On Browser" option, can launch a local program. The vulnerability carries a CVSS score of 8.8, indicating a high potential for impact (confidentiality, integrity, and availability) with low attack complexity, though user interaction is required. There is currently no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.0.20202.18177CPE matchmatch criteria | cpe:2.3:a:telerik:fiddler:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.