CVE-2020-29177: Critical severity z-blog vulnerability
Published Dec 2, 2021
·Updated
Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \appdel.php.
Affected Software
1 affected component
ZblogCN Z-blogphp=1.6.1.2100
Event History
Dec 2, 2021
CVE Published
via MITRE·10:21 PM
Data Sourced
via MITRE·10:21 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-29177.
2
What is the severity of CVE-2020-29177?
The severity of CVE-2020-29177 is critical with a CVSS score of 9.1.
3
What is the affected software?
The affected software is Z-BlogPHP version 1.6.1.2100.
4
How does the vulnerability work?
The vulnerability allows an attacker to delete arbitrary files through the \app_del.php file.
5
Is there a fix available for this vulnerability?
Yes, users should update to a patched version of Z-BlogPHP to fix this vulnerability.