CVE-2020-11107: Apachefriends Xampp
High severity, CVSS 8.8. EPSS: 22.5% chance of exploitation in the next 30 days.
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
Affected products
- Apachefriends Xampp: before 7.2.29 (fixed in 7.2.29); from 7.3.0, before 7.3.16 (fixed in 7.3.16); from 7.4.0, before 7.4.4 (fixed in 7.4.4)
Published 2020-04-02. Last modified 2026-06-17.