CVE-2020-13448: Quickbox

High severity, CVSS 8.8. EPSS: 17.4% chance of exploitation in the next 30 days.

QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.

Affected products

  • Quickbox Quickbox: up to and including 2.5.5; up to and including 2.1.8

Published 2020-06-01. Last modified 2026-06-17.