S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-28871 Scanner

CVE-2020-28871 scanner - Remote Code Execution (RCE) vulnerability in Monitorr

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-28871
9.8
CVSS

Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Monitorr is a web-based application used for the monitoring of multiple services and applications. It is primarily designed to keep an eye on various web services, servers, and APIs. The dashboard of this software displays real-time status updates, enabling the user to check their system's health at a glance. It also provides alert notifications and email notifications to ensure system administrators are informed of any outages or downtimes.

The CVE-2020-28871 vulnerability is a flaw that allowed an unauthorized individual to execute arbitrary code on the server-side of Monitorr v1.7.6m through an insecure file upload function in upload.php. An attacker could leverage the vulnerability to upload and execute files with dangerous payloads on Monitorr's server, thus causing severe harm.

Exploiting the vulnerability could lead to several undesirable consequences. For instance, unauthorized users could gain access to confidential information stored on the target server. In the wrong hands, Monitorr server's data could be used for malicious purposes like identity theft, phishing or further attacks on other systems. The exploitation of CVE-2020-28871 could thus turn a seemingly benign vulnerability into a serious security lapse resulting in loss of money, reputation and customer data.

In conclusion, the Monitorr v1.7.6m vulnerability is among the many security risks that can quickly translate into a significant data breach or a system compromise. It is thus essential to take adequate precautions to prevent hackers from exploiting such vulnerabilities. With s4e.io, you can easily and quickly learn about vulnerabilities in your digital assets, and also stay updated with the latest trends in cybersecurity to keep your systems secure from the ever-evolving threat landscape.

 

REFERENCES

Solution Advice

Protecting oneself from this vulnerability requires some basic security practices. They include:

  • Applying patches and updates regularly to avoid unpatched vulnerabilities
  • Deploying web application firewalls (WAFs) to detect and block attacker requests remotely
  • Using content-filters to sanitize user data input and prevent malicious uploads
  • Conducting security assessments regularly to identify vulnerabilities early on
  • Setting strong permissions for directory and file uploads

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.