ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36904”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36904
Published
2025-12-31
CVSS:
9.3
ShadowTrackr CVSS:
8.1
Summary:
Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication through the /cps/ endpoint and modify server configuration, including changing admin passwords and executing system commands.