First published: Wed Jun 16 2021(Updated: )
bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bloofox Bloofoxcms | =0.5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35762 is a vulnerability in bloofoxCMS 0.5.2.1 that allows attackers to read local files through a path traversal in the 'fileurl' parameter.
CVE-2020-35762 has a severity level of medium with a CVSS score of 2.7.
To fix CVE-2020-35762, update bloofoxCMS to version 0.5.2.1 or later.
You can find more information about CVE-2020-35762 on the GitHub issue page: https://github.com/alexlang24/bloofoxCMS/issues/11
The CWE for CVE-2020-35762 is CWE-22 (Path Traversal).