Vulnerabilities > CVE-2020-26207 - Deserialization of Untrusted Data vulnerability in Databaseschemareader Project Dbschemareader

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.

Vulnerable Configurations

Part Description Count
Application
Databaseschemareader_Project
36

Common Weakness Enumeration (CWE)