CVE-2020-25247: Path Traversal
An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. Directory traversal exists for writing to files, as demonstrated by the FileName parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25247?
CVE-2020-25247 has been classified as a high severity vulnerability due to the potential for directory traversal and unauthorized file writing.
How do I fix CVE-2020-25247?
To fix CVE-2020-25247, upgrade to a version of Hyland OnBase that is above 19.8.9.1000 or above 18.0.0.32.
What impact does CVE-2020-25247 have on Hyland OnBase installations?
CVE-2020-25247 allows attackers to perform directory traversal attacks, potentially leading to unauthorized access to system files.
Which versions of Hyland OnBase are affected by CVE-2020-25247?
CVE-2020-25247 affects Hyland OnBase versions up to 18.0.0.32 and from 19.0.0.0 to 19.8.9.1000.
Is CVE-2020-25247 exploitable remotely?
Yes, CVE-2020-25247 can be exploited remotely if an attacker can send crafted requests to the affected Hyland OnBase application.