CVE-2020-19360: Path Traversal
Published Jan 20, 2021
·Updated
Local file inclusion in FHEM 6.0 allows in fhem/FileLoglogWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.
Affected Software
1 affected component
FHEM FHEM=6.0
Event History
Jan 20, 2021
CVE Published
via MITRE·12:41 AM
Data Sourced
via MITRE·12:41 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-19360?
CVE-2020-19360 is classified as a medium severity vulnerability due to its potential for sensitive information disclosure.
2
How do I fix CVE-2020-19360?
To mitigate CVE-2020-19360, update FHEM to a version later than 6.0 where the vulnerability has been patched.
3
What software is affected by CVE-2020-19360?
CVE-2020-19360 specifically affects FHEM version 6.0.
4
What type of vulnerability is CVE-2020-19360?
CVE-2020-19360 is classified as a Local File Inclusion (LFI) vulnerability.
5
What could an attacker achieve using CVE-2020-19360?
An attacker exploiting CVE-2020-19360 could potentially include arbitrary files, leading to exposure of sensitive information.