CVE-2020-23489
AVideo vulnerable to Improper Privilege Management
8.8
HIGH
CVSS 3.1
EPSS 2.3%
描述
The import.json.php file before 8.9 for AVideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, causing certain privilege checks to not be in place, leading to privilege escalation to admin. Local File Inclusion may also leak credentials and important files. ### Patches Upgrade to version 8.9
如何修補 CVE-2020-23489
要修補 CVE-2020-23489,請將受影響套件升級到下列已修補版本。
- —升級至 8.9 或更新版本
CVE-2020-23489 正在被利用嗎?
低 — EPSS 為 2.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 8.9
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |