PT-2021-12074 · Unknown · Httpengine

Snyff

·

Published

2021-04-14

·

Updated

2025-04-11

·

CVE-2020-36559

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: HTTPEngine (affected versions not specified)
Description: The issue arises from improper sanitization of user input in HTTPEngine.Handle, allowing directory traversal. This enables an attacker to read files outside the target directory, provided the server has the necessary permissions to access those files.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-36559
GHSA-VP56-R7QV-783V
GO-2020-0033

Affected Products

Httpengine