CVE-2020-5590

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
19/06/2020
Last modified:
24/06/2020

Description

Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18 and 4.0.0 to 4.0.3 allows remote authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ec-cube:ec-cube:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.18 (including)
cpe:2.3:a:ec-cube:ec-cube:*:*:*:*:*:*:*:* 4.0.0 (including) 4.0.3 (including)