CVE-2020-35762: Path Traversal
Published Jun 16, 2021
·Updated
bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.
Affected Software
1 affected component
bloofox bloofoxCMS=0.5.2.1
Event History
Jun 16, 2021
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
Description
Frequently Asked Questions
1
What is CVE-2020-35762?
CVE-2020-35762 is a vulnerability in bloofoxCMS 0.5.2.1 that allows attackers to read local files through a path traversal in the 'fileurl' parameter.
2
How severe is CVE-2020-35762?
CVE-2020-35762 has a severity level of medium with a CVSS score of 2.7.
3
How can I fix CVE-2020-35762?
To fix CVE-2020-35762, update bloofoxCMS to version 0.5.2.1 or later.
4
Where can I find more information about CVE-2020-35762?
You can find more information about CVE-2020-35762 on the GitHub issue page: https://github.com/alexlang24/bloofoxCMS/issues/11
5
What is the CWE for CVE-2020-35762?
The CWE for CVE-2020-35762 is CWE-22 (Path Traversal).