S4E just found a medium log file scanner
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-19625 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Oria Gridx affects v. 1.3.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-19625
9.8
CVSS

Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Oria Gridx is a popular modular widget-based grid system used to create interactive data visualization tables and grids. It is widely utilized by web developers who want to display data in a structured and organized manner. The Oria Gridx provides a wide range of features that allow developers to customize the visual display of data according to their needs in a flexible manner.

However, recently, a vulnerability in the system was detected, specifically in the tests/support/stores/test_grid_filter.php file, identified as CVE-2020-19625. The vulnerability has exposed Oria Gridx to remote code execution attacks, which can allow a malicious actor to execute arbitrary code on the targeted system by sending crafted values to the $query parameter.

If this vulnerability is not patched or ignored, remote attackers could exploit this vulnerability to gain access to sensitive data stored on the system. They can execute arbitrary code, which can compromise the confidentiality, integrity, and availability of the digital assets. Furthermore, they can use the vulnerability to install malware and take control over the system, leading to significant financial losses and reputational damage.

In conclusion, it is crucial to stay informed about the latest vulnerabilities in your digital assets and take appropriate measures to protect them. s4e.io provides you with the pro features to identify vulnerabilities and helps you to keep track of them efficiently, enabling you to take corrective actions promptly. By keeping your digital assets secure, you will safeguard your data, processes, and reputation from malicious attacks.

 

REFERENCES

Solution Advice

Fortunately, there are some precautions that can be taken to minimize the risk of exploitation. Here are some of the best practices to follow:

  • Update Oria Gridx to the latest version as soon as possible.
  • Install web application firewalls (WAFs) that can identify and block attacks targeting the vulnerability.
  • Use a Content Security Policy (CSP) to restrict the sources of scripts, which can limit the ability of attackers to execute arbitrary code.
  • Disable the use of the unserialize function in the PHP configuration settings.
  • Implement access control and user permissions to restrict access to sensitive data and features only to authorized personnel.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-19625 scanner - Remote Code Execution (RCE) vulnerability in Oria Gridx S4E