CVE-2020-28145: High severity wuzhi cms vulnerability
Published Oct 12, 2021
·Updated
Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.0.1
Event History
Oct 12, 2021
CVE Published
via MITRE·10:21 AM
Data Sourced
via MITRE·10:21 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-28145.
2
What is the severity of CVE-2020-28145?
The severity of CVE-2020-28145 is high with a severity value of 7.5.
3
How does CVE-2020-28145 affect the Wuzhicms software?
CVE-2020-28145 affects Wuzhicms v4.0.1.
4
How can an attacker exploit CVE-2020-28145?
An attacker can exploit CVE-2020-28145 by accessing sensitive information through coreframe\app\attachment\admin\index.php.
5
Are there any references related to CVE-2020-28145?
Yes, you can find references related to CVE-2020-28145 at the following links: [Github](https://github.com/wuzhicms/wuzhicms/issues/191) and [CNVD](https://www.cnvd.org.cn/flaw/show/2394661).