CVE-2020-37086

Severity CVSS v4.0:
MEDIUM
Type:
CWE-22 Path Traversal
Publication date:
03/02/2026
Last modified:
03/02/2026

Description

Easy Transfer 1.7 iOS mobile application contains a directory traversal vulnerability that allows remote attackers to access unauthorized file system paths without authentication. Attackers can exploit the vulnerability by manipulating path parameters in GET and POST requests to list or download sensitive system files and inject malicious scripts into application parameters.