Description
The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.
No analysis available yet.
Remediation
Vendor Solution
Update to version 1.0.20.1109
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-18475 | The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4270-72392-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T19:25:28.103Z
Reserved: 2020-09-23T00:00:00.000Z
Link: CVE-2020-25842
No data.
Status : Modified
Published: 2020-12-31T08:15:12.423
Modified: 2024-11-21T05:18:53.050
Link: CVE-2020-25842
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD