CVE-2020-21527
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
30/09/2020
Last modified:
07/10/2020
Description
There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, when deleting their backup files, to delete any files on the system through directory traversal.
Impact
Base Score 3.x
7.70
Severity 3.x
HIGH
Base Score 2.0
8.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:halo:halo:1.1.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



