openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because jsonencodesafe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-26124.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.1.36"
}
]
},
{
"events": [
{
"introduced": "5.0.0"
},
{
"fixed": "5.5.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.1.36"
}
]
},
{
"events": [
{
"introduced": "5.x"
},
{
"fixed": "5.5.12"
}
]
}
]