VYPR
High severity8.8NVD Advisory· Published Nov 17, 2020· Updated Jun 17, 2026

CVE-2020-7841

CVE-2020-7841

Description

Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://

Affected products

3
  • cpe:2.3:a:tobesoft:xplatform:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:tobesoft:xplatform:*:*:*:*:*:*:*:*range: <9.2.2.250
    • (no CPE)
  • TOBESOFT/XPLATFORM XPlatformLib922.dllv5
    Range: 9.2.2.250

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.