CVE-2020-27976 describes a critical OS command injection vulnerability in osCommerce Phoenix CE versions prior to 1.0.5.4. This flaw, located in admin/mail.php, allows remote attackers to execute arbitrary commands by manipulating the 'from' POST parameter, which is then passed to the PHP mail function's sendmail -f option. With a CVSS score of 9.8 (CRITICAL), successful exploitation could lead to complete compromise of the affected system, requiring no user interaction or authentication. Despite its high severity and a FAUCET Risk Score of 94/100, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it shows minimal community discussion or media coverage, suggesting it is not actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.5.4CPE matchmatch criteria | cpe:2.3:a:oscommerce:oscommerce:*:*:*:*:phoenix:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.