PT-2020-18606 · Filezen · Filezen

Published

2020-12-14

·

Updated

2020-12-15

·

CVE-2020-5639

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FileZen versions 3.0.0 through 4.2.2
Description A directory traversal issue allows remote attackers to upload arbitrary files to specific directories via unspecified vectors, potentially leading to the execution of arbitrary OS commands.
Recommendations For versions 3.0.0 through 4.2.2, update to a version that contains a fix for this issue to prevent directory traversal and arbitrary file upload. As a temporary workaround, consider restricting access to sensitive directories and implementing additional security measures to prevent unauthorized file uploads.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5639

Affected Products

Filezen