ZeroHour

CVE-2020-36559

CVSS 3.1
7.5 high
EPSS
1%p65
Published
()
Modified
Description

Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

Vendors
aahframework
Products
aah
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.