← back
CVE-2020-7882highobserved exploitationCWE-24

anySign directory traversal vulnerability

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 7.5epss 1.2%
from disclosure to weapon
Published on NVDNov 22
VulnCheck+1435d
exploitation probability
1.2%top 35% of all CVEs
observed exploitation
yesVulnCheck
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Hancomwith · anySign4PC