CVE-2020-37012

Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /api.php endpoint. Attackers can craft a malicious LaTeX payload with shell commands that are executed when processed by the application's tex2png API action.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Tea LaTex 1.0 contiene una vulnerabilidad de ejecución remota de código que permite a atacantes no autenticados ejecutar comandos de shell arbitrarios a través del endpoint /api.php. Los atacantes pueden crear una carga útil LaTeX maliciosa con comandos de shell que se ejecutan cuando son procesados por la acción API tex2png de la aplicación.

29 Jan 2026, 17:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/48805 - () https://www.exploit-db.com/exploits/48805 -

29 Jan 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-29 15:16

Updated : 2026-04-15 00:35


NVD link : CVE-2020-37012

Mitre link : CVE-2020-37012

CVE.ORG link : CVE-2020-37012


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')