CVE-2020-37077

Severity CVSS v4.0:
MEDIUM
Type:
CWE-22 Path Traversal
Publication date:
03/02/2026
Last modified:
03/02/2026

Description

Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal techniques.