CVE-2020-7882

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
22/11/2021
Last modified:
26/11/2021

Description

Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hancom:anysign4pc:1.1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:hancom:anysign4pc:1.1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:hancom:anysign4pc:1.1.2.7:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*