CVE-2020-20948: High severity jeecg vulnerability
Published Dec 27, 2021
·Updated
An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.
Affected Software
1 affected component
Jeecg jeecg=3.8
Event History
Dec 27, 2021
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this arbitrary file download vulnerability?
The vulnerability ID of this arbitrary file download vulnerability is CVE-2020-20948.
2
What is the title of this vulnerability?
The title of this vulnerability is "An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the 'localPath' variable."
3
What is the affected software version of this vulnerability?
The affected software version of this vulnerability is jeecg v3.8.
4
How severe is this vulnerability?
This vulnerability is rated as high severity with a CVSS score of 7.5.
5
How can the attackers exploit this vulnerability?
Attackers can exploit this vulnerability by modifying the 'localPath' variable to gain unauthorized access to sensitive files.