VYPR

Score

by MediaWiki

CVEs (1)

  • CVE-2020-29007CriApr 15, 2023
    risk 0.64cvss 9.8epss 0.02

    The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary…