First published: Wed Jan 20 2021(Updated: )
Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foreman | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19360 is classified as a medium severity vulnerability due to its potential for sensitive information disclosure.
To mitigate CVE-2020-19360, update FHEM to a version later than 6.0 where the vulnerability has been patched.
CVE-2020-19360 specifically affects FHEM version 6.0.
CVE-2020-19360 is classified as a Local File Inclusion (LFI) vulnerability.
An attacker exploiting CVE-2020-19360 could potentially include arbitrary files, leading to exposure of sensitive information.