CVE-2020-21590: Path Traversal
Published Apr 2, 2021
·Updated
Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Apr 2, 2021
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-21590.
2
What is the title of this vulnerability?
The title of this vulnerability is "Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to...".
3
What is the description of this vulnerability?
The description of this vulnerability is "Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter."
4
What is the severity of CVE-2020-21590?
The severity of CVE-2020-21590 is medium with a severity value of 4.3.
5
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to update to a version of WUZHI CMS that is not affected by the vulnerability.