CVE-2020-23038: Path Traversal
Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter. This vulnerability is exploited via an error caused by including non-existent path environment variables.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-23038?
CVE-2020-23038 has been classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2020-23038?
To remediate CVE-2020-23038, update Swift File Transfer Mobile to version 1.1.3 or later where the vulnerability has been addressed.
Which versions are affected by CVE-2020-23038?
CVE-2020-23038 affects Swift File Transfer Mobile version 1.1.2 and below on Android and iPhone OS, as well as version 1.0.19 and lower on Blackberry.
What type of vulnerability is CVE-2020-23038?
CVE-2020-23038 is an information disclosure vulnerability that arises from improper handling of the path parameter.
How can CVE-2020-23038 be exploited?
CVE-2020-23038 can be exploited by including non-existent path environment variables, leading to exposure of sensitive information.