Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

J1Nse

#27879of 53,630
9.1Total CVSS
Vulnerabilities · 1
PT-2023-11762
9.1
2023-08-11
Zrlog · Zrlog · CVE-2020-27514
**Name of the Vulnerable Software and Affected Versions** ZrLog version 2.1.15 **Description** A Directory Traversal vulnerability exists in the delete function of the admin.api.TemplateController in ZrLog, allowing remote attackers to delete arbitrary files and cause a denial of service (DoS). **Recommendations** For ZrLog version 2.1.15, consider disabling the delete function in the admin.api.TemplateController until a patch is available to prevent remote attackers from deleting arbitrary files. Restrict access to the TemplateController to minimize the risk of exploitation.