CVE-2020-7522: Path Traversal
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of SoundUploadServlet which may lead to uploading executable files to non-specified directories.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7522?
CVE-2020-7522 is a Path Traversal vulnerability in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) that allows uploading executable files to non-specified directories.
What is the severity of CVE-2020-7522?
The severity of CVE-2020-7522 is critical with a severity score of 9.8.
How does CVE-2020-7522 occur?
CVE-2020-7522 occurs due to an improper limitation of a pathname to a restricted directory, allowing path traversal.
What is the affected software by CVE-2020-7522?
The affected software is Schneider-electric APC Easy UPS Online Software (V2.0 and earlier).
How can I fix CVE-2020-7522?
To fix CVE-2020-7522, it is recommended to update to a version higher than 2.0 of Schneider-electric APC Easy UPS Online Software.