CVE-2020-35970: SSRF
Published Jun 3, 2021
·Updated
An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.
Affected Software
1 affected component
YzmCMS YzmCMS=5.8
Event History
Jun 3, 2021
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35970?
CVE-2020-35970 is considered a medium severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2020-35970?
To fix CVE-2020-35970, update YzmCMS to the latest version that addresses this SSRF vulnerability.
3
What type of vulnerability is CVE-2020-35970?
CVE-2020-35970 is an SSRF vulnerability that allows for arbitrary file reading in YzmCMS.
4
What versions of YzmCMS are affected by CVE-2020-35970?
CVE-2020-35970 affects version 5.8 of YzmCMS.
5
Can CVE-2020-35970 lead to data exposure?
Yes, CVE-2020-35970 can lead to unauthorized access to sensitive files, resulting in data exposure.