PT-2020-18606 · Filezen · Filezen
Published
2020-12-14
·
Updated
2020-12-15
·
CVE-2020-5639
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FileZen versions 3.0.0 through 4.2.2
Description
A directory traversal issue allows remote attackers to upload arbitrary files to specific directories via unspecified vectors, potentially leading to the execution of arbitrary OS commands.
Recommendations
For versions 3.0.0 through 4.2.2, update to a version that contains a fix for this issue to prevent directory traversal and arbitrary file upload. As a temporary workaround, consider restricting access to sensitive directories and implementing additional security measures to prevent unauthorized file uploads.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filezen