First published: Fri May 21 2021(Updated: )
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server should they gain Administrator privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Htmly | =2.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-23766.
The severity of CVE-2020-23766 is medium with a score of 6.5.
CVE-2020-23766 allows remote attackers to use any absolute path to delete any file in the server if they gain Administrator privileges.
To fix CVE-2020-23766, it is recommended to update htmly to a version that addresses the vulnerability.
You can find more information about CVE-2020-23766 in the following reference: https://github.com/danpros/htmly/issues/412