CVE-2020-35388: High severity rainrocka xinhu vulnerability
Published Dec 26, 2020
·Updated
rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true.
Affected Software
1 affected component
Rockoa Xinhu=2.1.9
Event History
Dec 26, 2020
CVE Published
via MITRE·02:38 AM
Data Sourced
via MITRE·02:38 AM
Description
Frequently Asked Questions
1
What is CVE-2020-35388?
CVE-2020-35388 is a vulnerability in rainrocka xinhu 2.1.9 that allows remote attackers to obtain sensitive information.
2
How can remote attackers exploit CVE-2020-35388?
Remote attackers can exploit CVE-2020-35388 by manipulating the ajaxbool value in a index.php?a=gettotal request.
3
What is the severity of CVE-2020-35388?
The severity of CVE-2020-35388 is considered high with a severity value of 7.5.
4
What software versions are affected by CVE-2020-35388?
The vulnerability affects rainrocka xinhu 2.1.9.
5
Is there a fix for CVE-2020-35388?
It is recommended to update to a version of rainrocka xinhu that is not affected by this vulnerability.