Description
An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An attacker can download a file via a request of the form /common/download?filename=1.jsp&delete=false. NOTE: the software maintainer disputes the significance of this report because the product uses a JAR archive for deployment, and this contains application.yml with configuration data
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 20 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:58:19.079Z
Reserved: 2018-12-25T00:00:00.000Z
Link: CVE-2018-20437
Updated: 2024-08-05T11:58:19.079Z
Status : Modified
Published: 2018-12-25T15:29:00.240
Modified: 2024-11-21T04:01:28.877
Link: CVE-2018-20437
No data.
OpenCVE Enrichment
No data.
Weaknesses