ZeroHour

CVE-2020-36565

PoC
CVSS 3.1
5.3 medium
EPSS
1%p69
Published
()
Modified
Description

Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

Vendors
labstack
Products
echo
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.