ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37052”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37052
Published
2026-01-30
CVSS:
9.3
ShadowTrackr CVSS:
8.1
Summary:
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to run commands with the application's system privileges.