CWE
22 352
Advisory Published
Updated

CVE-2020-15182: Path Traversal

First published: Thu Sep 17 2020(Updated: )

The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit files once the administrator loads a specially crafted webpage. An administrator must be logged in for exploitation to be possible. This issue is fixed in SOY Inquiry version 2.0.0.4 and included in SOY CMS 3.0.2.328.

Credit: security-advisories@github.com

Affected SoftwareAffected VersionHow to fix
Soy Cms Project Soy Cms<3.0.2.328
Soy Inquiry Project Soy Inquiry<2.0.0.4

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2020-15182?

    CVE-2020-15182 is a vulnerability affecting the SOY Inquiry component of SOY CMS, allowing for Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE).

  • What is the severity of CVE-2020-15182?

    CVE-2020-15182 has a severity rating of 9.6, which is classified as critical.

  • What versions of SOY Inquiry are affected by CVE-2020-15182?

    Versions 2.0.0.3 and earlier of SOY Inquiry are affected by CVE-2020-15182.

  • How can remote attackers exploit CVE-2020-15182?

    Remote attackers can exploit CVE-2020-15182 to force administrators to edit files once the administrator loads a specially crafted page.

  • Where can I find more information about CVE-2020-15182?

    You can find more information about CVE-2020-15182 on GitHub Pull Request #15 and GitHub Security Advisories GHSA-j2qw-747j-mfv4. You can also watch a video demonstration at youtu.be/ffvKH3gwyRE.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203