CVE-2020-37245: WordPress Plugin Supsystic Digital Publications 1.6.9 Path Traversal XSS
Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stored cross-site scripting attacks through script injection in parameters like Area Width and Publication Width that execute when publications are viewed or edited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37245?
CVE-2020-37245 is considered a high-severity vulnerability due to its potential to allow unauthorized access to sensitive files on the server.
How do I fix CVE-2020-37245?
To fix CVE-2020-37245, update the Supsystic Digital Publications plugin to the latest version that addresses this vulnerability.
What kind of attack is possible with CVE-2020-37245?
CVE-2020-37245 allows attackers to perform a path traversal attack to access files outside the web root directory.
Who is affected by CVE-2020-37245?
CVE-2020-37245 affects users of the Supsystic Digital Publications plugin version 1.6.9.
Is CVE-2020-37245 exploitable remotely?
Yes, CVE-2020-37245 can be exploited remotely, making it a significant risk for web applications using the vulnerable plugin.