CVE-2020-14947: Factorfx Open Computer Software Inventory Next Generation
High severity, CVSS 8.8. EPSS: 19.5% chance of exploitation in the next 30 days.
OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.
Affected products
- Factorfx Open Computer Software Inventory Next Generation: version 2.7 only
Published 2020-06-30. Last modified 2026-06-17.