Vulnerabilities > CVE-2020-26207 - Deserialization of Untrusted Data vulnerability in Databaseschemareader Project Dbschemareader

047910
CVSS 8.0 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH

Summary

DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.

Vulnerable Configurations

Part Description Count
Application
Databaseschemareader_Project
36

Common Weakness Enumeration (CWE)