Wuzhicms · Wuzhi Cms · CVE-2020-21590
Name of the Vulnerable Software and Affected Versions:
WUZHI CMS version 4.1.0
Description:
The issue allows attackers to list files in arbitrary directories via the `dir` parameter in the coreframe/app/template/admin/index.php file. This is a directory traversal issue that can be exploited by attackers.
Recommendations:
For WUZHI CMS version 4.1.0, consider restricting access to the `dir` parameter in the coreframe/app/template/admin/index.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the `dir` parameter in the affected file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.