Vulnerability record · CVE-2020-35729 · published 27 December 2020
CVE-2020-35729: KLog Server authenticate.php OS command injection
Klogserver · Klog Server
KLog Server 2.4.1 passes the user parameter in actions/authenticate.php to a shell without sanitising shell metacharacters, allowing OS command injection. The flaw is remotely reachable and unauthenticated, and public exploit code exists, so any exposed instance is at immediate risk.
Description
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote OS command injection with a CVSS of 9.8 and very high EPSS plus public exploit code makes this an urgent patch-or-isolate case.
What it is
KLog Server 2.4.1 passes the user parameter in actions/authenticate.php to a shell without sanitising shell metacharacters, allowing OS command injection. The flaw is remotely reachable and unauthenticated, and public exploit code exists, so any exposed instance is at immediate risk.
Impact
An attacker can execute arbitrary operating system commands on the server, leading to full compromise of confidentiality, integrity and availability of the host and its log data.
Attack surface
Reached over the network via HTTP requests to actions/authenticate.php, specifically the user parameter. The CVSS vector indicates no privileges and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.881, 99.8th percentile) and multiple references are tagged Exploit, including public exploit code, indicating active and easy exploitation.
What to do
- Patch or upgrade KLog Server beyond 2.4.1 as soon as a fixed release is available; the record does not name a fixed version.
- If patching is not possible, remove KLog Server from internet exposure and restrict access to trusted management networks.
- Deploy a WAF or reverse proxy rule to block shell metacharacters in the user parameter of actions/authenticate.php.
- Run the KLog Server service under a low-privilege account with no shell and minimal filesystem permissions.
- Audit the host for signs of compromise and rotate any credentials stored or processed by the application.
Detection
- Monitor web logs for requests to actions/authenticate.php containing shell metacharacters (;, |, &, $, backticks) in the user parameter.
- Alert on unexpected child processes spawned by the web server or PHP process, especially shells and common command utilities.
- Review outbound network connections and file writes originating from the KLog Server process for signs of post-exploitation activity.
- Search host logs for command execution artifacts and unusual process trees on systems running KLog Server 2.4.1.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-35729 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35729), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.