CVE-2020-36142: Path Traversal
Published Jun 4, 2021
·Updated
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
Affected Software
1 affected component
bloofox bloofoxCMS=0.5.2.1
Event History
Jun 4, 2021
CVE Published
via MITRE·03:03 PM
Data Sourced
via MITRE·03:03 PM
Description
Frequently Asked Questions
1
What is CVE-2020-36142?
CVE-2020-36142 is a directory traversal vulnerability in BloofoxCMS 0.5.2.1 that allows an attacker to insert '../' payloads within the 'fileurl' parameter.
2
How severe is CVE-2020-36142?
The severity of CVE-2020-36142 is medium with a CVSS score of 6.5.
3
How does CVE-2020-36142 affect BloofoxCMS?
CVE-2020-36142 affects BloofoxCMS version 0.5.2.1.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-36142?
The CWE ID for CVE-2020-36142 is CWE-22.
5
Is there a patch or fix available for CVE-2020-36142?
At this time, it is recommended to update BloofoxCMS to a version that addresses the vulnerability.