Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the ‘AjaxRun()’ function.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26772
Reference (s):
- https://blog.csdn.net/qq_33020901/article/details/108938473
- https://github.com/george518/PPGo_Job/issues/56

